2026 CVE Vulnerabilities
48,535 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8496 | MEDIUM | 6.1 | 0.4% | May 13, 2026 | A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar in... |
| CVE-2026-42580 | MEDIUM | 6.5 | 0.4% | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, Netty's c... |
| CVE-2026-41255 | MEDIUM | 6.1 | 0.1% | May 13, 2026 | CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5... |
| CVE-2026-33584 | MEDIUM | 5.3 | 0.3% | May 13, 2026 | Exposed Keycloak management service in the Arqit Symmetric Key Agreement Platform enables unauthorized access to sensit... |
| CVE-2026-30904 | MEDIUM | 4.3 | 0.1% | May 13, 2026 | Protection Mechanism Failure in Zoom Workplace for iOS before version 7.0.0 may allow an authenticated user to conduct a... |
| CVE-2026-22677 | MEDIUM | 6.5 | 0.4% | May 13, 2026 | Hermes WebUI prior to 0.51.44 contains a path traversal vulnerability in the session import endpoint that allows authent... |
| CVE-2026-0256 | MEDIUM | 4.8 | 0.3% | May 13, 2026 | A stored cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticat... |
| CVE-2026-0249 | MEDIUM | 6.5 | 0.1% | May 13, 2026 | Multiple improper certificate validation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enables an attacke... |
| CVE-2026-0248 | MEDIUM | 5.9 | 0.1% | May 13, 2026 | An improper certificate validation vulnerability in the Prisma Access Agent® for Android and Chrome OS enables an attack... |
| CVE-2026-0245 | MEDIUM | 5.5 | 0.1% | May 13, 2026 | Multiple information disclosure vulnerabilities in Prisma Access Agent® allow a local user to access sensitive configura... |
| CVE-2026-0242 | MEDIUM | 6.1 | 0.2% | May 13, 2026 | A SQL injection vulnerability in Trust Protection Foundation allows an authenticated attacker to execute arbitrary SQL c... |
| CVE-2026-0239 | MEDIUM | 6.5 | 0.2% | May 13, 2026 | An information disclosure vulnerability in the Chronosphere Chronocollector enables an unauthenticated attacker with net... |
| CVE-2026-0235 | MEDIUM | 4.7 | 0.2% | May 13, 2026 | A race condition vulnerability in Palo Alto Networks Prisma® Browser enables a locally authenticated non-admin user to b... |
| CVE-2026-44581 | MEDIUM | 4.7 | 0.2% | May 13, 2026 | Next.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Rou... |
| CVE-2026-44580 | MEDIUM | 6.1 | 0.2% | May 13, 2026 | Next.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applica... |
| CVE-2026-44003 | MEDIUM | 5.8 | 0.2% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's code transformer has a performance optimization tha... |
| CVE-2026-44002 | MEDIUM | 5.8 | 0.2% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's CallSite wrapper class (intended as a safe wrapper ... |
| CVE-2026-44577 | MEDIUM | 5.9 | 0.7% | May 13, 2026 | Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when se... |
| CVE-2026-44576 | MEDIUM | 5.4 | 0.3% | May 13, 2026 | Next.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applica... |
| CVE-2026-2695 | MEDIUM | 6.3 | 0.2% | May 13, 2026 | A command injection vulnerability was discovered in TeamViewer DEX Platform On-Premises (former 1E DEX Platform On-Premi... |
| CVE-2026-8367 | MEDIUM | 5.3 | 0.1% | May 13, 2026 | aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (... |
| CVE-2026-45028 | MEDIUM | 6.1 | 0.1% | May 13, 2026 | Astro is a web framework. Astro versions prior to 6.1.10 used AES-GCM encryption to protect the confidentiality and inte... |
| CVE-2026-44665 | MEDIUM | 6.1 | 0.2% | May 13, 2026 | fast-xml-builder builds XML from JSON. Prior to 1.1.7, when an input data has quotes in attribute values but process ent... |
| CVE-2026-44664 | MEDIUM | 6.1 | 0.2% | May 13, 2026 | fast-xml-builder builds XML from JSON. In 1.1.5, the fix for CVE-2026-41650 in fast-xml-parser sanitizes -- sequences in... |
| CVE-2026-44572 | MEDIUM | 5.9 | 0.2% | May 13, 2026 | Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an exte... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now