2026 CVE Vulnerabilities
48,518 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8669 | MEDIUM | 6.5 | 0.3% | May 15, 2026 | Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager:... |
| CVE-2026-39053 | MEDIUM | 6.5 | 0.4% | May 15, 2026 | Oinone Pamirs 7.0.0 contains an XML External Entity (XXE) issue in its XStream-based XML parsing logic. When attacker-co... |
| CVE-2026-39052 | MEDIUM | 6.5 | 0.3% | May 15, 2026 | Oinone Pamirs 7.0.0 contains a code execution vulnerability via ScriptRunner. The method ScriptRunner.run(String express... |
| CVE-2026-8503 | MEDIUM | 6.5 | 0.2% | May 15, 2026 | Apache::Session::Generate::SHA256 versions before 1.3.19 for Perl create insecure session ids. Apache::Session::Generat... |
| CVE-2026-8454 | MEDIUM | 5.3 | 0.2% | May 15, 2026 | Imager::File::GIF versions through 1.002 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF file... |
| CVE-2026-41971 | MEDIUM | 5.5 | 0.1% | May 15, 2026 | Permission control vulnerability in the security control module. Impact: Successful exploitation of this vulnerability m... |
| CVE-2026-41970 | MEDIUM | 6.8 | 0.1% | May 15, 2026 | Out-of-bounds write vulnerability in the distributed file system module. Impact: Successful exploitation of this vulnera... |
| CVE-2026-41969 | MEDIUM | 6.2 | 0.1% | May 15, 2026 | Permission control vulnerability in the projection module. Impact: Successful exploitation of this vulnerability may aff... |
| CVE-2026-41968 | MEDIUM | 5.9 | 0.1% | May 15, 2026 | Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnera... |
| CVE-2026-41967 | MEDIUM | 5.9 | 0.1% | May 15, 2026 | Permission control vulnerability in the manufacturability design module. Impact: Successful exploitation of this vulnera... |
| CVE-2026-41966 | MEDIUM | 5.6 | 0.1% | May 15, 2026 | Permission control vulnerability in the smart sensing service. Impact: Successful exploitation of this vulnerability may... |
| CVE-2026-41965 | MEDIUM | 5.6 | 0.1% | May 15, 2026 | Use-After-Free (UAF) vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availabi... |
| CVE-2026-41961 | MEDIUM | 5.9 | 0.1% | May 15, 2026 | Permission control vulnerability in contacts. Impact: Successful exploitation of this vulnerability may affect availabil... |
| CVE-2026-41960 | MEDIUM | 5.8 | 0.1% | May 15, 2026 | Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability... |
| CVE-2026-8425 | MEDIUM | 4.3 | 0.1% | May 15, 2026 | The Notify Odoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1... |
| CVE-2026-7563 | MEDIUM | 4.3 | 0.3% | May 15, 2026 | The Classified Listing – AI-Powered Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to una... |
| CVE-2026-7046 | MEDIUM | 4.9 | 0.4% | May 15, 2026 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to time-based blind SQL Injection... |
| CVE-2026-6415 | MEDIUM | 6.4 | 0.3% | May 15, 2026 | The Advanced Custom Fields: Font Awesome plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions u... |
| CVE-2026-4683 | MEDIUM | 6.5 | 0.3% | May 15, 2026 | The Smartcat Translator for WPML plugin for WordPress is vulnerable to unauthorized modification of data due to a missin... |
| CVE-2026-6646 | MEDIUM | 6.4 | 0.3% | May 15, 2026 | The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dt_default_button' shortcode in all v... |
| CVE-2026-24662 | MEDIUM | 5.4 | 0.1% | May 15, 2026 | Cross-site scripting vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and ear... |
| CVE-2026-0427 | MEDIUM | 4.6 | 0.1% | May 15, 2026 | Improper cleanup of shared register resources in GPU firmware could allow an admin-privileged attacker from a Guest Virt... |
| CVE-2026-8612 | MEDIUM | 5.3 | 0.1% | May 15, 2026 | WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cac... |
| CVE-2026-0438 | MEDIUM | 5.4 | 0.1% | May 15, 2026 | A System Management Mode (SMM) handler could perform a callout to code located in non-SMM/untrusted memory. A highly pri... |
| CVE-2026-6811 | MEDIUM | 6 | 0.3% | May 14, 2026 | Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSO... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now