2026 CVE Vulnerabilities
48,883 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44029 | MEDIUM | 5.3 | 0.6% | May 5, 2026 | An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "n... |
| CVE-2026-7783 | MEDIUM | 6.3 | 0.2% | May 5, 2026 | A flaw has been found in CodeCanyon Perfex CRM up to 3.4.1. This vulnerability affects the function AbstractKanban::appl... |
| CVE-2026-7782 | MEDIUM | 6.3 | 0.2% | May 4, 2026 | A vulnerability was detected in CodeCanyon Perfex CRM up to 3.4.1. This affects the function Clients::project of the fil... |
| CVE-2026-7781 | MEDIUM | 4.3 | 0.3% | May 4, 2026 | A security vulnerability has been detected in Open5GS up to 2.7.7. Affected by this issue is the function udm_nudm_uecm_... |
| CVE-2026-7780 | MEDIUM | 4.3 | 0.3% | May 4, 2026 | A weakness has been identified in Open5GS up to 2.7.7. Affected by this vulnerability is the function udm_state_operatio... |
| CVE-2026-7779 | MEDIUM | 4.3 | 0.4% | May 4, 2026 | A security flaw has been discovered in Open5GS up to 2.7.7. Affected is the function udm_nudr_dr_handle_subscription_aut... |
| CVE-2026-42223 | MEDIUM | 6.5 | 0.3% | May 4, 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, the GetSettings API handler (api/sett... |
| CVE-2026-42220 | MEDIUM | 6.5 | 0.3% | May 4, 2026 | Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, an authenticated user can call GET /a... |
| CVE-2026-42230 | MEDIUM | 6.1 | 0.2% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /mcp-oauth/regis... |
| CVE-2026-42228 | MEDIUM | 6.5 | 0.4% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket ... |
| CVE-2026-42227 | MEDIUM | 6.5 | 0.2% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated use... |
| CVE-2026-41686 | MEDIUM | 4.4 | 0.1% | May 4, 2026 | Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From... |
| CVE-2026-42146 | MEDIUM | 5.5 | 0.1% | May 4, 2026 | CImg Library is a C++ library for image processing. Prior to commit c3aacf5, the nb_colors field read from the BMP file ... |
| CVE-2026-42144 | MEDIUM | 6.1 | 0.1% | May 4, 2026 | CImg Library is a C++ library for image processing. Prior to commit 4ca26bc, there is an integer overflow vulnerability ... |
| CVE-2026-42140 | MEDIUM | 4.4 | 0.2% | May 4, 2026 | PlantUML Macro is a macro for rendering UML diagrams from simple textual schemes. Prior to version 2.4.1, the PlantUML M... |
| CVE-2026-42138 | MEDIUM | 6.1 | 0.2% | May 4, 2026 | Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, a... |
| CVE-2026-42092 | MEDIUM | 6.5 | 0.2% | May 4, 2026 | titra is an open source time tracking project. In version 0.99.52, the globalsettings Meteor publication returns all glo... |
| CVE-2026-42091 | MEDIUM | 6.5 | 0.2% | May 4, 2026 | goshs is a SimpleHTTPServer written in Go. Prior to version 2.0.2, the PUT upload handler (httpserver/updown.go) lacks t... |
| CVE-2026-42086 | MEDIUM | 4.6 | 0.2% | May 4, 2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2026-42085 | MEDIUM | 4.3 | 0.3% | May 4, 2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2026-42052 | MEDIUM | 6 | 0.3% | May 4, 2026 | Beets is the media library management system. Prior to version 2.10.0, the bundled web UI uses Underscore template inter... |
| CVE-2026-41572 | MEDIUM | 5.3 | 0.2% | May 4, 2026 | Note Mark is an open-source note-taking application. Prior to version 0.19.3, after a note-mark owner soft-deletes a pub... |
| CVE-2026-42080 | MEDIUM | 4.6 | 0.2% | May 4, 2026 | PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, there is an arbitrary fi... |
| CVE-2026-42078 | MEDIUM | 4.6 | 0.2% | May 4, 2026 | PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable t... |
| CVE-2026-42077 | MEDIUM | 5.2 | 0.1% | May 4, 2026 | Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a prototype pollution vulnerabilit... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now