2026 CVE Vulnerabilities
48,546 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20718 | MEDIUM | 5.4 | 0.1% | May 12, 2026 | Incorrect default permissions for some Intel(R) NPU Driver software installers before version 32.0.100.4511 within Ring ... |
| CVE-2026-20717 | MEDIUM | 6.6 | 0.1% | May 12, 2026 | Improper input validation for some Intel(R) QAT software drivers for Windows before version 1.13 within Ring 3: User App... |
| CVE-2026-8368 | MEDIUM | 6.5 | 0.3% | May 12, 2026 | LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirect... |
| CVE-2026-8109 | MEDIUM | 6.5 | 0.7% | May 12, 2026 | An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authen... |
| CVE-2026-7431 | MEDIUM | 4.4 | 0.2% | May 12, 2026 | An incorrect permission assignment for critical resource of Ivanti Secure Access Client before 22.8R6 allows a local a... |
| CVE-2026-5061 | MEDIUM | 4.7 | 0.1% | May 12, 2026 | The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper tha... |
| CVE-2026-8391 | MEDIUM | 5.3 | 0.3% | May 12, 2026 | Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Fir... |
| CVE-2026-8388 | MEDIUM | 6.5 | 0.2% | May 12, 2026 | Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3, ... |
| CVE-2026-43930 | MEDIUM | 5.9 | 0.2% | May 12, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76 ... |
| CVE-2026-42006 | MEDIUM | 4.3 | 0.6% | May 12, 2026 | An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomple... |
| CVE-2026-40638 | MEDIUM | 6.7 | 0.1% | May 12, 2026 | Dell PowerScale InsightIQ, versions 5.0.0 through 6.2.0, contains an execution with unnecessary privileges vulnerability... |
| CVE-2026-40020 | MEDIUM | 4.3 | 0.3% | May 12, 2026 | Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_all... |
| CVE-2026-40016 | MEDIUM | 6.5 | 0.3% | May 12, 2026 | Attacker can upload a malicious Sieve script over ManageSieve service (or locally) to bypass configured CPU time limits ... |
| CVE-2026-33603 | MEDIUM | 5.3 | 0.2% | May 12, 2026 | Attacker can use a specially crafted base64 exchange between Dovecot and Client to fake SCRAM TLS channel binding. This ... |
| CVE-2026-45215 | MEDIUM | 5.3 | 0.2% | May 12, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal WP EasyPay wp-easy-pay allows Retrieve Emb... |
| CVE-2026-45212 | MEDIUM | 5.3 | 0.2% | May 12, 2026 | Missing Authorization vulnerability in Gabe Livan Asset CleanUp: Page Speed Booster wp-asset-clean-up allows Exploiting ... |
| CVE-2026-45210 | MEDIUM | 5.4 | 0.2% | May 12, 2026 | Missing Authorization vulnerability in Broadstreet Broadstreet Ads broadstreet allows Exploiting Incorrectly Configured ... |
| CVE-2026-6813 | MEDIUM | 4.4 | 0.2% | May 12, 2026 | The Continually plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up ... |
| CVE-2026-6800 | MEDIUM | 4.4 | 0.2% | May 12, 2026 | The FastBots plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to,... |
| CVE-2026-41125 | MEDIUM | 6 | 0.2% | May 12, 2026 | A vulnerability has been identified in blueplanet 100 NX3 M8 (All versions), blueplanet 100 TL3 GEN2 (All versions), blu... |
| CVE-2026-33862 | MEDIUM | 6.1 | 0.2% | May 12, 2026 | A vulnerability has been identified in Teamcenter V2312 (All versions < V2312.0014), Teamcenter V2406 (All versions < V2... |
| CVE-2026-1934 | MEDIUM | 4.3 | 0.2% | May 12, 2026 | The Motors – Car Dealership & Classified Listings plugin for WordPress is vulnerable to Payment Bypass via insecure user... |
| CVE-2026-7661 | MEDIUM | 6.4 | 0.2% | May 12, 2026 | The Bootstrap Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `box` shortcode in all... |
| CVE-2026-7659 | MEDIUM | 6.4 | 0.2% | May 12, 2026 | The Advanced Social Media Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `social` short... |
| CVE-2026-7626 | MEDIUM | 5.3 | 0.3% | May 12, 2026 | The Slek Gateway for WooCommerce plugin for WordPress is vulnerable to Information Exposure in version 1.0. This is due ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now