2026 CVE Vulnerabilities
48,557 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42314 | MEDIUM | 6.5 | 0.3% | May 11, 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, package folder names are s... |
| CVE-2026-42312 | MEDIUM | 6.8 | 0.2% | May 11, 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API... |
| CVE-2026-41257 | MEDIUM | 5.5 | 0.1% | May 11, 2026 | jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in... |
| CVE-2026-41256 | MEDIUM | 5.5 | 0.2% | May 11, 2026 | jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncate... |
| CVE-2026-41250 | MEDIUM | 5.7 | 0.3% | May 11, 2026 | Taiga is a project management platform for startups and agile developers. Prior 6.9.1, Taiga front is vulnerable to stor... |
| CVE-2026-40612 | MEDIUM | 5.5 | 0.2% | May 11, 2026 | jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth... |
| CVE-2026-3048 | MEDIUM | 5.1 | 0.3% | May 11, 2026 | An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3... |
| CVE-2026-38569 | MEDIUM | 5.4 | 0.2% | May 11, 2026 | HireFlow v1.2 is vulnerable to Cross Site Scripting (XSS) in candidate_detail.html via the Resume or Feedback Comment fi... |
| CVE-2026-34095 | MEDIUM | 6.1 | 0.2% | May 11, 2026 | Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Actions/... |
| CVE-2026-34093 | MEDIUM | 5.3 | 0.2% | May 11, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulne... |
| CVE-2026-44737 | MEDIUM | 6.2 | 0.3% | May 11, 2026 | grav-plugin-admin is the admin plugin for Grav is an HTML user interface that provides a convenient way to configure Gra... |
| CVE-2026-42842 | MEDIUM | 5.4 | 0.1% | May 11, 2026 | The form plugin for Grav adds the ability to create and use forms. Prior to 9.1.0, a Stored Cross-Site Scripting (XSS) v... |
| CVE-2026-36906 | MEDIUM | 6.1 | 0.3% | May 11, 2026 | Cross Site Scripting vulnerability in iotgateway v.3.0.1 allows a remote attacker to execute arbitrary code via the Log ... |
| CVE-2026-31252 | MEDIUM | 5.7 | 0.1% | May 11, 2026 | CosyVoice thru commit 6e01309e01bc93bbeb83bdd996b1182a81aaf11e (2025-30-21) contains an insecure deserialization vulnera... |
| CVE-2026-8292 | MEDIUM | 6.5 | 0.4% | May 11, 2026 | A security vulnerability has been detected in Open5GS up to 2.7.7. The affected element is the function yuarel_parse in ... |
| CVE-2026-8291 | MEDIUM | 6.5 | 0.4% | May 11, 2026 | A weakness has been identified in Open5GS up to 2.7.7. Impacted is the function ogs_nnrf_nfm_handle_nf_profile of the fi... |
| CVE-2026-7820 | MEDIUM | 6.9 | 0.2% | May 11, 2026 | Improper restriction of excessive authentication attempts (CWE-307) in pgAdmin 4. pgAdmin enforces MAX_LOGIN_ATTEMPTS o... |
| CVE-2026-7814 | MEDIUM | 4.8 | 0.2% | May 11, 2026 | Stored cross-site scripting (XSS) vulnerability in pgAdmin 4 Browser Tree and Explain Visualizer modules. User-controll... |
| CVE-2026-6815 | MEDIUM | 5.9 | 0.5% | May 11, 2026 | An arbitrary file write vulnerability exists in Casdoor's Local File System storage provider. Due to insufficient path s... |
| CVE-2026-6093 | MEDIUM | 6 | 0.2% | May 11, 2026 | Corteza contains a SQL injection vulnerability in its Microsoft SQL Server (MSSQL) backend when filtering Compose record... |
| CVE-2026-44201 | MEDIUM | 5.3 | 0.3% | May 11, 2026 | Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, the Documents and I... |
| CVE-2026-44200 | MEDIUM | 6.5 | 0.2% | May 11, 2026 | Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with lim... |
| CVE-2026-44199 | MEDIUM | 6.5 | 0.2% | May 11, 2026 | Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user with lim... |
| CVE-2026-44198 | MEDIUM | 4.3 | 0.2% | May 11, 2026 | Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without ... |
| CVE-2026-44197 | MEDIUM | 6.5 | 0.2% | May 11, 2026 | Wagtail is an open source content management system built on Django. Prior to 7.0.7, 7.3.2, and 7.4, a CMS user without ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now