2026 CVE Vulnerabilities
48,527 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42572 | MEDIUM | 6.5 | 0.2% | May 14, 2026 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.83.39, a... |
| CVE-2026-41888 | MEDIUM | 6.5 | 0.3% | May 14, 2026 | Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELE... |
| CVE-2026-45448 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | CWE-601 URL redirection to untrusted site ('open redirect') |
| CVE-2026-44514 | MEDIUM | 6.5 | 0.2% | May 14, 2026 | Kubetail is a real-time logging dashboard for Kubernetes. Prior to 0.14.0, Kubetail's dashboard exposes WebSocket endpoi... |
| CVE-2026-44312 | MEDIUM | 5.8 | 0.1% | May 14, 2026 | css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Parser gem does not validate HTTPS connections, allo... |
| CVE-2026-20210 | MEDIUM | 5.4 | 0.2% | May 14, 2026 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, r... |
| CVE-2026-20209 | MEDIUM | 5.4 | 0.2% | May 14, 2026 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, r... |
| CVE-2026-42597 | MEDIUM | 5.9 | 0.3% | May 14, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the /forms/chromium/convert/url and /forms/c... |
| CVE-2026-42593 | MEDIUM | 5.3 | 0.3% | May 14, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, pdfengines/merge, pdfengines/split, libreoff... |
| CVE-2026-42592 | MEDIUM | 5.3 | 0.2% | May 14, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, FilterOutboundURL resolves the hostname, che... |
| CVE-2026-42159 | MEDIUM | 5.4 | 0.2% | May 14, 2026 | Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri... |
| CVE-2026-44374 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | Backstage is an open framework for building developer portals. Prior to 0.6.11, the unprocessed entities read endpoints ... |
| CVE-2026-44371 | MEDIUM | 5.3 | 0.3% | May 14, 2026 | Open OnDemand is an open-source high-performance computing portal. Prior to 4.0.11, 4.1.5, and 4.2.2, specially crafted ... |
| CVE-2026-44308 | MEDIUM | 6.3 | 0.2% | May 14, 2026 | Spring Cloud AWS simplifies using AWS managed services in a Spring and Spring Boot applications. From 3.0.0 to 4.0.1, pp... |
| CVE-2026-41933 | MEDIUM | 6.9 | 0.2% | May 14, 2026 | Vvveb before 1.0.8.3 contains a directory listing information disclosure vulnerability that allows unauthenticated attac... |
| CVE-2026-41932 | MEDIUM | 6.1 | 0.2% | May 14, 2026 | Vvveb before 1.0.8.3 contains a stored cross-site scripting vulnerability in the customer signup flow where the Signup::... |
| CVE-2026-24711 | MEDIUM | 5.3 | 0.2% | May 14, 2026 | Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 has Incorrect Access Control. |
| CVE-2026-24710 | MEDIUM | 6.1 | 0.2% | May 14, 2026 | Northern.tech CFEngine Enterprise before 3.21.8, 3.24.3, and 3.27.0 allows XSS. |
| CVE-2026-21730 | MEDIUM | 6.1 | 0.2% | May 14, 2026 | Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism. When an unaut... |
| CVE-2026-6575 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | Buffer over-read in PostgreSQL function pg_restore_attribute_stats() accepts array values of unmatched length, which cau... |
| CVE-2026-6478 | MEDIUM | 6.5 | 0.6% | May 14, 2026 | Covert timing channel in comparison of MD5-hashed password in PostgreSQL authentication allows an attacker to recover us... |
| CVE-2026-6474 | MEDIUM | 4.3 | 0.2% | May 14, 2026 | Externally-controlled format string in PostgreSQL timeofday() function allows an attacker to retrieve portions of server... |
| CVE-2026-6472 | MEDIUM | 5.4 | 0.2% | May 14, 2026 | Missing authorization in PostgreSQL CREATE TYPE allows an object creator to hijack other queries that use search_path to... |
| CVE-2026-1630 | MEDIUM | 5.1 | 0.4% | May 14, 2026 | WEBCON BPS is vulnerable to Reflected XSS via one of parameters used by "/openinmobileapp" endpoint. An attacker can sen... |
| CVE-2026-6008 | MEDIUM | 6.8 | 0.2% | May 14, 2026 | Authorization bypass through User-Controlled key vulnerability in Im Park Information Technology, Electronics, Press, Pu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now