2026 CVE Vulnerabilities
48,561 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6667 | MEDIUM | 4.3 | 0.3% | May 9, 2026 | PgBouncer before 1.25.2 did not perform an appropriate authorization check for the KILL_CLIENT admin command. All users ... |
| CVE-2026-45130 | MEDIUM | 5.5 | 0.2% | May 8, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0450, a heap buffer overflow exists in read_compou... |
| CVE-2026-44656 | MEDIUM | 5.3 | 0.9% | May 8, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists... |
| CVE-2026-44284 | MEDIUM | 6.3 | 0.2% | May 8, 2026 | FastGPT is an AI Agent building platform. Prior to version 4.14.17, FastGPT had an inconsistent SSRF protection gap in M... |
| CVE-2026-42456 | MEDIUM | 4.3 | 0.3% | May 8, 2026 | AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatti... |
| CVE-2026-42451 | MEDIUM | 6.3 | 0.1% | May 8, 2026 | Grimmory is a self-hosted digital library. Prior to version 2.3.1, a stored cross-site scripting (XSS) vulnerability in ... |
| CVE-2026-42350 | MEDIUM | 5.1 | 0.2% | May 8, 2026 | Kargo manages and automates the promotion of software artifacts. Prior to versions 1.7.10, 1.8.13, 1.9.8, and 1.10.2, Ka... |
| CVE-2026-42346 | MEDIUM | 6.5 | 0.2% | May 8, 2026 | Postiz is an AI social media scheduling tool. From version 2.16.6 to before version 2.21.7, all SSRF protections added i... |
| CVE-2026-42344 | MEDIUM | 6.3 | 0.1% | May 8, 2026 | FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packa... |
| CVE-2026-42343 | MEDIUM | 6.3 | 0.3% | May 8, 2026 | FastGPT is an AI Agent building platform. In versions 4.14.13 and prior, the code-sandbox component suffers from insuffi... |
| CVE-2026-42307 | MEDIUM | 4.4 | 0.8% | May 8, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0383, an OS command injection vulnerability exists... |
| CVE-2026-42291 | MEDIUM | 6.8 | 0.2% | May 8, 2026 | SysReptor is a fully customizable pentest reporting platform. From version 2026.4 to before version 2026.27, the endpoin... |
| CVE-2026-41682 | MEDIUM | 6.9 | 0.3% | May 8, 2026 | pupnp is an SDK for development of UPnP device and control point applications. Prior to version 1.18.5, pupnp is vulnera... |
| CVE-2026-41520 | MEDIUM | 4.4 | 0.1% | May 8, 2026 | Cilium is a networking, observability, and security solution with an eBPF-based dataplane. Prior to versions 1.17.15, 1.... |
| CVE-2026-42213 | MEDIUM | 5.1 | 0.5% | May 8, 2026 | SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.... |
| CVE-2026-42209 | MEDIUM | 6.5 | 0.4% | May 8, 2026 | FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.1, a remote client with reta... |
| CVE-2026-42206 | MEDIUM | 5.7 | 0.2% | May 8, 2026 | Roadiz is a polymorphic content management system based on a node system. Prior to versions 2.3.43, 2.5.45, 2.6.31, and ... |
| CVE-2026-42202 | MEDIUM | 6.5 | 0.2% | May 8, 2026 | nova-toggle-5 enables fliping booleans in the index. Prior to version 1.3.0, the toggle endpoint (POST/nova-vendor/nova-... |
| CVE-2026-42199 | MEDIUM | 6.2 | 0.1% | May 8, 2026 | Grid is a data structure grid for rust. From version 0.17.0 to before version 1.0.1, an integer overflow in Grid::expand... |
| CVE-2026-42192 | MEDIUM | 5.4 | 0.2% | May 8, 2026 | Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, a stored cross-site scripting (X... |
| CVE-2026-42282 | MEDIUM | 4.3 | 0.3% | May 8, 2026 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior... |
| CVE-2026-42190 | MEDIUM | 5.3 | 0.1% | May 8, 2026 | RedwoodSDK is a server-first React framework. From version 1.0.0-beta.50 to before version 1.2.3, server actions in rwsd... |
| CVE-2026-42185 | MEDIUM | 5.5 | 0.3% | May 8, 2026 | People is an application to handle users and teams, and distribute permissions across La Suite. Prior to version 1.25.0,... |
| CVE-2026-42181 | MEDIUM | 6.5 | 0.2% | May 8, 2026 | Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy fetches metadata for user-suppli... |
| CVE-2026-42180 | MEDIUM | 6.3 | 0.2% | May 8, 2026 | Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy allows an authenticated low-priv... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now