2026 CVE Vulnerabilities
48,877 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-5766 | MEDIUM | 6.3 | 0.4% | May 5, 2026 | An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-... |
| CVE-2026-43073 | MEDIUM | 5.5 | 0.1% | May 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: x86-64: rename misleadingly named '__copy_user_noca... |
| CVE-2026-43072 | MEDIUM | 5.5 | 0.1% | May 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/vc4: platform_get_irq_byname() returns an int ... |
| CVE-2026-43069 | MEDIUM | 5.5 | 0.1% | May 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_ll: Fix firmware leak on error path ... |
| CVE-2026-43068 | MEDIUM | 5.5 | 0.1% | May 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: ext4: avoid allocate block from corrupted group in ... |
| CVE-2026-43066 | MEDIUM | 5.5 | 0.1% | May 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: ext4: fix iloc.bh leak in ext4_fc_replay_inode() er... |
| CVE-2026-43065 | MEDIUM | 5.5 | 0.1% | May 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: ext4: always drain queued discard work in ext4_mb_r... |
| CVE-2026-43064 | MEDIUM | 5.5 | 0.1% | May 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix not releasing workqueue on .re... |
| CVE-2026-43061 | MEDIUM | 5.5 | 0.1% | May 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: serial: 8250: Fix TX deadlock when using DMA `dmae... |
| CVE-2026-39103 | MEDIUM | 5.5 | 0.1% | May 5, 2026 | Buffer Overflow vulnerability in GPAC before commit v391dc7f4d234988ea0bc3cc294eb725eddf8f702 allows an attacker to caus... |
| CVE-2026-35192 | MEDIUM | 6.5 | 0.5% | May 5, 2026 | An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session ... |
| CVE-2026-34956 | MEDIUM | 5.9 | 0.4% | May 5, 2026 | A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the users... |
| CVE-2026-7778 | MEDIUM | 5 | 0.2% | May 5, 2026 | An issue that could allow a dashboard configuration to be viewed from outside of the authorized organization scope has b... |
| CVE-2026-30246 | MEDIUM | 6.5 | 0.3% | May 5, 2026 | Fiber is a web framework for Go. In github.com/gofiber/fiber/v3 versions through 3.1.0, the default key generator in the... |
| CVE-2026-28510 | MEDIUM | 5.9 | 0.3% | May 5, 2026 | eLabFTW is an open source electronic lab notebook. In elabftw versions through 5.4.1, the login flow did not reliably pr... |
| CVE-2026-27694 | MEDIUM | 5.4 | 0.2% | May 5, 2026 | Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the ema... |
| CVE-2026-27693 | MEDIUM | 5.4 | 0.2% | May 5, 2026 | Traccar is an open source GPS tracking system. In org.traccar:traccar versions starting at 6.11.1 before 6.13.0, the KML... |
| CVE-2026-27644 | MEDIUM | 6.5 | 0.2% | May 5, 2026 | Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality write... |
| CVE-2026-6262 | MEDIUM | 6.5 | 0.3% | May 5, 2026 | The Betheme theme for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 28.4. This is... |
| CVE-2026-43574 | MEDIUM | 6.5 | 0.2% | May 5, 2026 | OpenClaw before 2026.4.12 contains an improper authorization vulnerability in helper-backed channels where empty resolve... |
| CVE-2026-43572 | MEDIUM | 6.3 | 0.2% | May 5, 2026 | OpenClaw versions 2026.4.10 before 2026.4.14 contain a missing authorization vulnerability in the Microsoft Teams SSO in... |
| CVE-2026-43570 | MEDIUM | 6.5 | 0.3% | May 5, 2026 | OpenClaw versions 2026.3.22 before 2026.4.5 contain a symlink traversal vulnerability in remote marketplace repository p... |
| CVE-2026-43868 | MEDIUM | 5.3 | 0.7% | May 5, 2026 | Memory Allocation with Excessive Size Value vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.... |
| CVE-2026-3601 | MEDIUM | 4.3 | 0.3% | May 5, 2026 | The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a miss... |
| CVE-2026-7824 | MEDIUM | 5.9 | 0.2% | May 5, 2026 | An issue was discovered in the PaperCut Hive Ricoh embedded application. When the "Deep Logging" (diagnostic) mode is en... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now