2026 CVE Vulnerabilities
48,557 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45025 | MEDIUM | 6.8 | 0.2% | May 11, 2026 | WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vuln... |
| CVE-2026-42887 | MEDIUM | 4.5 | 0.2% | May 11, 2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.33.0, a stored cross-site scripting (XSS) vulne... |
| CVE-2026-42886 | MEDIUM | 4.9 | 0.3% | May 11, 2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the POST /api/backups/upload endpoint dec... |
| CVE-2026-42885 | MEDIUM | 4.3 | 0.2% | May 11, 2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the POST /api/filesystem/pathexists endpo... |
| CVE-2026-42884 | MEDIUM | 4.3 | 0.2% | May 11, 2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/collections and GET /api/col... |
| CVE-2026-42883 | MEDIUM | 6.5 | 0.2% | May 11, 2026 | Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/libraries/:id/download endpo... |
| CVE-2026-42876 | MEDIUM | 4.9 | 0.2% | May 11, 2026 | External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete... |
| CVE-2026-42875 | MEDIUM | 5.3 | 0.2% | May 11, 2026 | External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernete... |
| CVE-2026-42872 | MEDIUM | 6.1 | 0.2% | May 11, 2026 | WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a reflected Cross-Site Scripting (XSS) v... |
| CVE-2026-42870 | MEDIUM | 6.4 | 0.3% | May 11, 2026 | WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a Stored Cross-Site Scripting (XSS) flaw... |
| CVE-2026-42565 | MEDIUM | 4.3 | 0.2% | May 11, 2026 | @workos/authkit-session is a toolkit for building WorkOS AuthKit framework integrations. Prior to 0.5.1, an open redirec... |
| CVE-2026-42050 | MEDIUM | 5.5 | 0.1% | May 11, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-21 and 6.9... |
| CVE-2026-8318 | MEDIUM | 5.5 | 0.4% | May 11, 2026 | A security flaw has been discovered in VectifyAI PageIndex up to f50e52975313c6716c02b20a119577a1929decba. Affected by t... |
| CVE-2026-45222 | MEDIUM | 6.9 | 0.1% | May 11, 2026 | Summarize versions through 0.14.1, fixed in commit 0cfb0fb, creates the daemon configuration directory and file with def... |
| CVE-2026-43968 | MEDIUM | 4 | 0.2% | May 11, 2026 | Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows SSE event splittin... |
| CVE-2026-42871 | MEDIUM | 6.9 | 0.3% | May 11, 2026 | WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, atendido/familiar_docfamiliar.php displa... |
| CVE-2026-42866 | MEDIUM | 6.7 | 0.1% | May 11, 2026 | Tookie is a advanced OSINT information gathering tool. Prior to 4.1fix, modules/modules.py's write_txt, write_csv, write... |
| CVE-2026-7308 | MEDIUM | 5.1 | 0.3% | May 11, 2026 | An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript t... |
| CVE-2026-4893 | MEDIUM | 5.3 | 2.7% | May 11, 2026 | An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS pac... |
| CVE-2026-4891 | MEDIUM | 5.3 | 6.2% | May 11, 2026 | A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a den... |
| CVE-2026-45005 | MEDIUM | 6 | 0.3% | May 11, 2026 | OpenClaw before 2026.4.23 caches resolved webhook route secrets backed by SecretRef values, allowing stale secrets to re... |
| CVE-2026-45003 | MEDIUM | 5 | 0.1% | May 11, 2026 | OpenClaw before 2026.4.22 allows workspace dotenv files to override connector endpoint hosts for Matrix, Mattermost, IRC... |
| CVE-2026-45002 | MEDIUM | 6.3 | 0.3% | May 11, 2026 | OpenClaw before 2026.4.20 contains a hook session-key bypass vulnerability that allows attackers to circumvent the hooks... |
| CVE-2026-45000 | MEDIUM | 5 | 0.2% | May 11, 2026 | OpenClaw before 2026.4.20 contains a server-side request forgery vulnerability in browser CDP profile creation that skip... |
| CVE-2026-44999 | MEDIUM | 6.3 | 0.2% | May 11, 2026 | OpenClaw before 2026.4.20 fails to properly preserve untrusted labels for isolated cron awareness events, allowing webho... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now