2026 CVE Vulnerabilities
48,542 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8200 | MEDIUM | 5.3 | 0.2% | May 13, 2026 | When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the loc... |
| CVE-2026-44352 | MEDIUM | 5.3 | 0.2% | May 12, 2026 | Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri... |
| CVE-2026-44347 | MEDIUM | 6.5 | 0.1% | May 12, 2026 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.23.3, the SSO flow does not validate ... |
| CVE-2026-44341 | MEDIUM | 5.3 | 0.2% | May 12, 2026 | GoJobs is a REST API for a Job Board platform. The application exposes a job retrieval endpoint that allows unauthentica... |
| CVE-2026-44245 | MEDIUM | 6.1 | 0.2% | May 12, 2026 | Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 2.5.2, Vue 3's v-html directiv... |
| CVE-2026-42157 | MEDIUM | 5.1 | 0.3% | May 12, 2026 | Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri... |
| CVE-2026-44306 | MEDIUM | 5.3 | 0.2% | May 12, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.21 and 6.15.0, responses from the f... |
| CVE-2026-44305 | MEDIUM | 6.8 | 0.1% | May 12, 2026 | Lemur manages TLS certificate creation. Prior to 1.9.0, when LDAP TLS is enabled (LDAP_USE_TLS = True), Lemur's LDAP aut... |
| CVE-2026-44259 | MEDIUM | 4.6 | 0.1% | May 12, 2026 | efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the previewServlet serves files with their detected MIME t... |
| CVE-2026-42545 | MEDIUM | 5.9 | 0.2% | May 12, 2026 | Granian is a Rust HTTP server for Python applications. From 0.2.0 to 2.7.4, Granian aborts a worker process if a WSGI ap... |
| CVE-2026-41195 | MEDIUM | 5 | 0.2% | May 12, 2026 | mosparo is the modern solution to protect your online forms from spam. Prior to 1.4.13, the automatic rule package sourc... |
| CVE-2026-33570 | MEDIUM | 6.9 | 0.2% | May 12, 2026 | PowerSYSTEM Center REST API endpoint for devices allows a low privilege authenticated user to access information normall... |
| CVE-2026-35504 | MEDIUM | 5.5 | 0.3% | May 12, 2026 | PowerSYSTEM Center email notification service is affected by a CRLF injection vulnerability when using SMTPS communicati... |
| CVE-2026-8052 | MEDIUM | 6 | 0.1% | May 12, 2026 | HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as ... |
| CVE-2026-6959 | MEDIUM | 6 | 0.2% | May 12, 2026 | HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host a... |
| CVE-2026-44874 | MEDIUM | 4.9 | 0.3% | May 12, 2026 | A vulnerability exists in the web-based management interface of an AOS-10 Gateway that could allow an authenticated remo... |
| CVE-2026-44873 | MEDIUM | 5.4 | 0.1% | May 12, 2026 | A session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their a... |
| CVE-2026-44223 | MEDIUM | 6.5 | 0.4% | May 12, 2026 | vLLM is an inference and serving engine for large language models (LLMs). From 0.18.0 to before 0.20.0, the extract_hidd... |
| CVE-2026-44217 | MEDIUM | 6.6 | 0.4% | May 12, 2026 | sse-channel is an SSE-implementation which can be used to any node.js http request/response stream. Prior to 4.0.1, impl... |
| CVE-2026-42445 | MEDIUM | 5.5 | 0.1% | May 12, 2026 | NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability ex... |
| CVE-2026-42444 | MEDIUM | 5.5 | 0.1% | May 12, 2026 | NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a denial-of-service vulnerability exists i... |
| CVE-2026-42443 | MEDIUM | 5.5 | 0.1% | May 12, 2026 | NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an integer divide-by-zero exists in the UF... |
| CVE-2026-42442 | MEDIUM | 5.5 | 0.1% | May 12, 2026 | NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, a null-pointer dereference exists in the U... |
| CVE-2026-42355 | MEDIUM | 5.5 | 0.1% | May 12, 2026 | NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability ex... |
| CVE-2026-42338 | MEDIUM | 6.1 | 0.5% | May 12, 2026 | ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.gr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now