2026 CVE Vulnerabilities
48,605 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39817 | MEDIUM | 5.9 | 0.2% | May 7, 2026 | The "go tool pack" subcommand (usually used only by the compiler as an internal tool with known-good inputs) does not sa... |
| CVE-2026-8084 | MEDIUM | 5.5 | 0.3% | May 7, 2026 | A vulnerability was determined in OSGeo gdal up to 3.13.0dev-4. This vulnerability affects the function memmove of the f... |
| CVE-2026-44742 | MEDIUM | 6.1 | 0.2% | May 7, 2026 | Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as e... |
| CVE-2026-41903 | MEDIUM | 5.4 | 0.3% | May 7, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user hold... |
| CVE-2026-8081 | MEDIUM | 6.3 | 0.2% | May 7, 2026 | A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by this issue is some unknown functionality... |
| CVE-2026-36388 | MEDIUM | 5.4 | 0.1% | May 7, 2026 | A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/... |
| CVE-2026-36387 | MEDIUM | 6.5 | 0.3% | May 7, 2026 | A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This... |
| CVE-2026-36341 | MEDIUM | 5.4 | 0.2% | May 7, 2026 | Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supp... |
| CVE-2026-44264 | MEDIUM | 4.3 | 0.3% | May 7, 2026 | Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other... |
| CVE-2026-44263 | MEDIUM | 4.3 | 0.3% | May 7, 2026 | Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowe... |
| CVE-2026-41689 | MEDIUM | 6 | 0.2% | May 7, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the webhook notifica... |
| CVE-2026-41687 | MEDIUM | 4.3 | 0.2% | May 7, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 4.8.1, the SSRF protection in en... |
| CVE-2026-41650 | MEDIUM | 6.1 | 0.2% | May 7, 2026 | fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Prior to version ... |
| CVE-2026-41519 | MEDIUM | 5.4 | 0.2% | May 7, 2026 | Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions ... |
| CVE-2026-32686 | MEDIUM | 6.9 | 0.3% | May 7, 2026 | Uncontrolled Resource Consumption vulnerability in ericmj decimal allows unauthenticated remote Denial of Service. The ... |
| CVE-2026-41685 | MEDIUM | 4.3 | 0.3% | May 7, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.0.0, uploads of large amount of data by auth... |
| CVE-2026-41684 | MEDIUM | 6.5 | 0.4% | May 7, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.0.0, backup.GetInfo() trusts the inline back... |
| CVE-2026-41648 | MEDIUM | 5 | 0.3% | May 7, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.0.0, user provided image and backup tarballs... |
| CVE-2026-41647 | MEDIUM | 6.5 | 0.4% | May 7, 2026 | Incus is a system container and virtual machine manager. Prior to version 7.0.0, a missing error handling could lead an ... |
| CVE-2026-5791 | MEDIUM | 6.5 | 0.1% | May 7, 2026 | Cross-Site request forgery (CSRF) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross Site... |
| CVE-2026-8080 | MEDIUM | 5.4 | 0.1% | May 7, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in misp allows... |
| CVE-2026-33589 | MEDIUM | 6.5 | 0.2% | May 7, 2026 | Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to ac... |
| CVE-2026-27415 | MEDIUM | 4.3 | 0.1% | May 7, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in PluginUs.Net BEAR allows Cross Site Request Forgery. This issue affe... |
| CVE-2026-27421 | MEDIUM | 6.5 | 0.2% | May 7, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WProyal Royal Elem... |
| CVE-2026-27416 | MEDIUM | 5.3 | 0.2% | May 7, 2026 | Missing Authorization vulnerability in bPlugins PDF Poster allows Exploiting Incorrectly Configured Access Control Secur... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now