2026 CVE Vulnerabilities
48,517 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44560 | MEDIUM | 6.5 | 0.4% | May 15, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the t... |
| CVE-2026-44559 | MEDIUM | 4.3 | 0.2% | May 15, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the G... |
| CVE-2026-44558 | MEDIUM | 5.4 | 0.2% | May 15, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the c... |
| CVE-2026-44557 | MEDIUM | 4.3 | 0.2% | May 15, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the _... |
| CVE-2026-44550 | MEDIUM | 5 | 0.3% | May 15, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Folde... |
| CVE-2026-4054 | MEDIUM | 6.5 | 0.2% | May 15, 2026 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to validate the response body of proxie... |
| CVE-2026-4053 | MEDIUM | 4.3 | 0.2% | May 15, 2026 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fiel... |
| CVE-2026-46365 | MEDIUM | 5.4 | 0.2% | May 15, 2026 | phpMyFAQ before 4.1.2 contains a missing authorization vulnerability in the DELETE /admin/api/content/tags/{tagId} endpo... |
| CVE-2026-46363 | MEDIUM | 5.4 | 0.2% | May 15, 2026 | phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in FAQ creation and update endpoints that byp... |
| CVE-2026-46360 | MEDIUM | 5.4 | 0.2% | May 15, 2026 | phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in SvgSanitizer::decodeAllEntities() that lim... |
| CVE-2026-45622 | MEDIUM | 5.3 | 0.3% | May 15, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3... |
| CVE-2026-45616 | MEDIUM | 5.1 | 0.2% | May 15, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3... |
| CVE-2026-45009 | MEDIUM | 5.3 | 0.2% | May 15, 2026 | phpMyFAQ before 4.1.2 contains an insufficient authorization vulnerability in admin-api routes that allows authenticated... |
| CVE-2026-45007 | MEDIUM | 5.3 | 0.2% | May 15, 2026 | phpMyFAQ before 4.1.2 contains missing permission checks in ConfigurationTabController.php where 12 endpoints use userIs... |
| CVE-2026-44719 | MEDIUM | 5.3 | 0.3% | May 15, 2026 | Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to befor... |
| CVE-2026-44718 | MEDIUM | 5.3 | 0.3% | May 15, 2026 | Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to befor... |
| CVE-2026-44366 | MEDIUM | 6.1 | 0.3% | May 15, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.1... |
| CVE-2026-46383 | MEDIUM | 5.5 | 0.6% | May 15, 2026 | Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0, Microsoft APM conta... |
| CVE-2026-44310 | MEDIUM | 5.4 | 0.1% | May 15, 2026 | Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. From 0.4.0 to before 0... |
| CVE-2026-44309 | MEDIUM | 5.3 | 0.1% | May 15, 2026 | Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. Prior to 0.16.0, gitsi... |
| CVE-2026-42458 | MEDIUM | 5.3 | 0.3% | May 15, 2026 | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun... |
| CVE-2026-42207 | MEDIUM | 6.1 | 0.1% | May 15, 2026 | Magento Long Term Support (LTS) is an unofficial, community-driven project provides an alternative to the Magento Commun... |
| CVE-2026-41181 | MEDIUM | 5.8 | 0.4% | May 15, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.44, 3.6.15, and 3.7.0-rc.3, there is an information di... |
| CVE-2026-23695 | MEDIUM | 5.4 | 0.1% | May 15, 2026 | Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a stored cross-site scripting vulnerability in t... |
| CVE-2026-45773 | MEDIUM | 6.5 | 0.1% | May 15, 2026 | Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14, Turborepo's self-... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now