2026 CVE Vulnerabilities
48,557 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42841 | MEDIUM | 4.8 | 0.4% | May 11, 2026 | Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with page editing permissions can inject... |
| CVE-2026-42612 | MEDIUM | 5.4 | 0.2% | May 11, 2026 | Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a stored Cross-Site Scripting (XSS) vulnerability in getgrav/g... |
| CVE-2026-42610 | MEDIUM | 6.5 | 0.3% | May 11, 2026 | Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.upda... |
| CVE-2026-3320 | MEDIUM | 5.1 | 0.3% | May 11, 2026 | Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input ... |
| CVE-2026-3319 | MEDIUM | 5.1 | 0.3% | May 11, 2026 | Reflected Cross-Site Scripting (XSS) in the latest demo version of the Cradle eCommerce platform. User-controlled input ... |
| CVE-2026-31246 | MEDIUM | 6.5 | 0.7% | May 11, 2026 | GPT-Pilot thru commit 0819827ce20346ef5f25b3fe29293cb448840565 (2025-09-03) contains a command injection vulnerability (... |
| CVE-2026-8290 | MEDIUM | 6.5 | 0.4% | May 11, 2026 | A security flaw has been discovered in Open5GS up to 2.7.7. This issue affects the function smf_nsmf_handle_update_data_... |
| CVE-2026-8289 | MEDIUM | 6.5 | 0.4% | May 11, 2026 | A vulnerability was identified in Open5GS up to 2.7.7. This vulnerability affects the function smf_nsmf_handle_update_da... |
| CVE-2026-8288 | MEDIUM | 6.5 | 0.4% | May 11, 2026 | A vulnerability was determined in Open5GS up to 2.7.7. This affects the function gsm_handle_pdu_session_modification_qos... |
| CVE-2026-6956 | MEDIUM | 5.1 | 0.4% | May 11, 2026 | ATutor is vulnerable to Reflected XSS in /install/install.php endpoint. An attacker can provide a specially crafted URL ... |
| CVE-2026-6909 | MEDIUM | 5.1 | 0.4% | May 11, 2026 | ATutor is vulnerable to Reflected XSS in /install/upgrade.php endpoint. An attacker can provide a specially crafted URL ... |
| CVE-2026-26946 | MEDIUM | 6.7 | 0.1% | May 11, 2026 | Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains an improper privilege... |
| CVE-2026-43826 | MEDIUM | 6.5 | 0.4% | May 11, 2026 | The OpenSearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:pa... |
| CVE-2026-41018 | MEDIUM | 6.5 | 0.4% | May 11, 2026 | The Elasticsearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user... |
| CVE-2026-5084 | MEDIUM | 6.5 | 0.3% | May 11, 2026 | WebDyne::Session versions before 3.003_704 for Perl generate the session id insecurely. The session handler generates t... |
| CVE-2026-1677 | MEDIUM | 5.3 | 0.2% | May 11, 2026 | Zephyr sockets created with `IPPROTO_TLS_1_3` can still negotiate a TLS 1.2 connection when both TLS versions are enable... |
| CVE-2026-8274 | MEDIUM | 5.3 | 0.2% | May 11, 2026 | A security vulnerability has been detected in npitre cramfs-tools up to 2.1. Affected is the function do_directory of th... |
| CVE-2026-8270 | MEDIUM | 6.5 | 0.4% | May 11, 2026 | A vulnerability was determined in Open5GS up to 2.7.7. The affected element is the function ogs_nas_parse_qos_rules of t... |
| CVE-2026-8269 | MEDIUM | 6.5 | 0.5% | May 11, 2026 | A vulnerability was found in Open5GS up to 2.7.7. Impacted is the function smf_nsmf_handle_create_sm_context of the comp... |
| CVE-2026-8268 | MEDIUM | 6.5 | 0.4% | May 11, 2026 | A vulnerability has been found in Open5GS up to 2.7.7. This issue affects the function OpenAPI_list_create of the compon... |
| CVE-2026-8267 | MEDIUM | 6.5 | 0.4% | May 11, 2026 | A flaw has been found in Open5GS up to 2.7.7. This vulnerability affects the function smf_nsmf_handle_created_data_in_vs... |
| CVE-2026-8266 | MEDIUM | 6.5 | 0.5% | May 11, 2026 | A vulnerability was detected in Open5GS up to 2.7.7. This affects the function gsm_build_pdu_session_establishment_accep... |
| CVE-2026-8261 | MEDIUM | 5.9 | 0.2% | May 11, 2026 | A vulnerability was determined in Squirrel up to 3.2. This affects the function SQFunctionProto::Load of the file squirr... |
| CVE-2026-8258 | MEDIUM | 5.3 | 0.1% | May 11, 2026 | A flaw has been found in Squirrel up to 3.2. Impacted is the function validate_format in the library sqstdlib/sqstdstrin... |
| CVE-2026-8257 | MEDIUM | 5.5 | 0.2% | May 11, 2026 | A vulnerability was detected in WebAssembly Binaryen up to 117. This issue affects the function IRBuilder::makeBrOn of t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now