2026 CVE Vulnerabilities
48,532 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44423 | MEDIUM | 6.5 | 0.2% | May 13, 2026 | ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/sessions/:uid returns the full session object for any a... |
| CVE-2026-44195 | MEDIUM | 6.5 | 0.3% | May 13, 2026 | OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockout_handler... |
| CVE-2026-8328 | MEDIUM | 5.9 | 0.5% | May 13, 2026 | The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4189 was fixed. While makepasv() was patched to rep... |
| CVE-2026-45228 | MEDIUM | 5.4 | 0.2% | May 13, 2026 | Quark Drive before 0.8.5 contains a stored cross-site scripting vulnerability in the System Configuration page where the... |
| CVE-2026-45054 | MEDIUM | 4.9 | 0.2% | May 13, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.0, the admin orders-transactions listing page (admin.php?_g=ord... |
| CVE-2026-44381 | MEDIUM | 5.3 | 0.2% | May 13, 2026 | MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed ... |
| CVE-2026-44379 | MEDIUM | 5.3 | 0.2% | May 13, 2026 | MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, MISP Collections did not enforce RFC 4... |
| CVE-2026-44376 | MEDIUM | 6.1 | 0.7% | May 13, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.0, an unauthenticated Reflected XSS vulnerability exists in the... |
| CVE-2026-44373 | MEDIUM | 5.3 | 0.4% | May 13, 2026 | Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could bypass a proxy route rule by send... |
| CVE-2026-44372 | MEDIUM | 6.1 | 0.2% | May 13, 2026 | Nitro is a next generation server toolkit. Prior to 3.0.260429-beta, an attacker could turn a redirect route rule using ... |
| CVE-2026-44368 | MEDIUM | 6.9 | 0.3% | May 13, 2026 | PyQuorum is a cryptographic library for secret sharing and key management. Prior to 0.2.1, the mul_mod function implemen... |
| CVE-2026-39428 | MEDIUM | 4.8 | 0.2% | May 13, 2026 | CubeCart is an ecommerce software solution. Prior to 6.6.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in ... |
| CVE-2026-44363 | MEDIUM | 5.8 | 0.1% | May 13, 2026 | MISP modules are autonomous modules that can be used to extend MISP for new services. Prior to 3.0.7, an unsafe remote r... |
| CVE-2026-42549 | MEDIUM | 4.4 | 0.2% | May 13, 2026 | Flight is an extensible micro-framework for PHP. Prior to 3.18.1, the make:controller CLI command calls mkdir(..., recur... |
| CVE-2026-33380 | MEDIUM | 6.5 | 0.3% | May 13, 2026 | A vulnerability in SQL Expressions allows an authenticated attacker to read arbitrary files from the Grafana server's fi... |
| CVE-2026-33378 | MEDIUM | 6.5 | 0.3% | May 13, 2026 | Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the s... |
| CVE-2026-28383 | MEDIUM | 6.5 | 0.3% | May 13, 2026 | A request to the Grafana plugin resources endpoint can cause unbounded memory allocation by reading the entire request b... |
| CVE-2026-28380 | MEDIUM | 6.5 | 0.2% | May 13, 2026 | Any Editor could delete any snapshot, even if they have no access to read or write them. |
| CVE-2026-28379 | MEDIUM | 6.5 | 0.3% | May 13, 2026 | A race condition in Grafana Live allows authenticated users with Viewer role to trigger a server crash by sending concur... |
| CVE-2026-28376 | MEDIUM | 6.5 | 0.3% | May 13, 2026 | The Grafana Live push endpoint can be exploited to cause unbounded memory allocation by sending a large or streaming req... |
| CVE-2026-28374 | MEDIUM | 4.3 | 0.2% | May 13, 2026 | Editors could delete any annotation, even those they do not have read access to. The editor user cannot create or read t... |
| CVE-2026-0243 | MEDIUM | 6.5 | 0.2% | May 13, 2026 | A denial of service (DoS) vulnerability in Palo Alto Networks Prisma SD-WAN ION devices enables an unauthenticated attac... |
| CVE-2026-8496 | MEDIUM | 6.1 | 0.4% | May 13, 2026 | A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar in... |
| CVE-2026-42580 | MEDIUM | 6.5 | 0.4% | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's c... |
| CVE-2026-41255 | MEDIUM | 6.1 | 0.1% | May 13, 2026 | CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now