2026 CVE Vulnerabilities
48,542 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34688 | MEDIUM | 6.2 | 0.3% | May 12, 2026 | CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Improper Input Validation v... |
| CVE-2026-34680 | MEDIUM | 6.2 | 0.3% | May 12, 2026 | CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Integer Overflow or Wraparo... |
| CVE-2026-34679 | MEDIUM | 6.2 | 0.2% | May 12, 2026 | CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Improper Input Validation v... |
| CVE-2026-34678 | MEDIUM | 6.2 | 0.2% | May 12, 2026 | CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consu... |
| CVE-2026-34677 | MEDIUM | 6.2 | 0.2% | May 12, 2026 | CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consu... |
| CVE-2026-34673 | MEDIUM | 6.2 | 0.2% | May 12, 2026 | CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Uncontrolled Resource Consu... |
| CVE-2026-34672 | MEDIUM | 6.2 | 0.3% | May 12, 2026 | CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Integer Underflow (Wrap or ... |
| CVE-2026-34671 | MEDIUM | 6.2 | 0.2% | May 12, 2026 | CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Integer Overflow or Wraparo... |
| CVE-2026-34670 | MEDIUM | 6.2 | 0.3% | May 12, 2026 | CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Improper Input Validation v... |
| CVE-2026-34669 | MEDIUM | 6.2 | 0.2% | May 12, 2026 | CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Improper Input Validation v... |
| CVE-2026-34668 | MEDIUM | 6.2 | 0.2% | May 12, 2026 | CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Improper Input Validation v... |
| CVE-2026-34667 | MEDIUM | 6.2 | 0.2% | May 12, 2026 | CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Integer Underflow (Wrap or ... |
| CVE-2026-34666 | MEDIUM | 6.2 | 0.3% | May 12, 2026 | CAI Content Credentials versions c2pa-web@0.7.0, c2pa-v0.78.2 and earlier are affected by an Improper Input Validation v... |
| CVE-2026-34658 | MEDIUM | 4.8 | 0.3% | May 12, 2026 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a s... |
| CVE-2026-34656 | MEDIUM | 4.3 | 0.4% | May 12, 2026 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an ... |
| CVE-2026-34655 | MEDIUM | 4.8 | 0.4% | May 12, 2026 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a s... |
| CVE-2026-34654 | MEDIUM | 5.3 | 0.6% | May 12, 2026 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a D... |
| CVE-2026-34664 | MEDIUM | 6.3 | 0.2% | May 12, 2026 | Substance3D - Designer versions 15.1.0 and earlier are affected by an Improper Limitation of a Pathname to a Restricted ... |
| CVE-2026-23822 | MEDIUM | 5.3 | 0.3% | May 12, 2026 | A vulnerability in the XML handling component of AOS-8 DHCP services could allow an unauthenticated remote attacker to t... |
| CVE-2026-5146 | MEDIUM | 4.3 | 0.2% | May 12, 2026 | Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacke... |
| CVE-2026-44279 | MEDIUM | 5.5 | 0.1% | May 12, 2026 | An improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, Forti... |
| CVE-2026-44278 | MEDIUM | 5.5 | 0.1% | May 12, 2026 | A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindo... |
| CVE-2026-44204 | MEDIUM | 6.5 | 0.2% | May 12, 2026 | Shelf is a platform for tracking physical assets. From 1.12 to before 1.20.1, a SQL injection vulnerability in the sortB... |
| CVE-2026-42891 | MEDIUM | 6.5 | 0.3% | May 12, 2026 | User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized ... |
| CVE-2026-42838 | MEDIUM | 5.4 | 0.2% | May 12, 2026 | Improper neutralization of special elements in output used by a downstream component ('injection') in Microsoft Edge (Ch... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now