2026 CVE Vulnerabilities
49,638 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47266 | HIGH | 8.7 | 0.3% | May 29, 2026 | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.21 and 3.1.26, unauthenticated users could modify existing... |
| CVE-2026-47123 | HIGH | 7.5 | 0.1% | May 29, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.220, the email processin... |
| CVE-2026-46599 | HIGH | 7.5 | 0.4% | May 29, 2026 | The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit... |
| CVE-2026-46527 | HIGH | 7.5 | 0.3% | May 29, 2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, When the server has c... |
| CVE-2026-46385 | HIGH | 7.5 | 0.5% | May 29, 2026 | iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map decoders looped over an attacker-contro... |
| CVE-2026-46384 | HIGH | 7.5 | 0.5% | May 29, 2026 | iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, several Avro decoder paths read attacker-controlled 64-bit val... |
| CVE-2026-45352 | HIGH | 7.5 | 0.3% | May 29, 2026 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size i... |
| CVE-2026-45149 | HIGH | 7.5 | 0.3% | May 29, 2026 | The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.... |
| CVE-2026-44422 | HIGH | 8.8 | 0.4% | May 29, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts on... |
| CVE-2026-44421 | HIGH | 8.8 | 0.5% | May 29, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a h... |
| CVE-2026-44420 | HIGH | 8.8 | 3.7% | May 29, 2026 | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a h... |
| CVE-2026-44285 | HIGH | 7.7 | 0.3% | May 29, 2026 | FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allo... |
| CVE-2026-49382 | HIGH | 7.8 | 0.1% | May 29, 2026 | In JetBrains IntelliJ IDEA before 2026.1 code execution was possible via template injection in the Copyright plugin |
| CVE-2026-49374 | HIGH | 7.6 | 0.2% | May 29, 2026 | In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters |
| CVE-2026-49373 | HIGH | 8.8 | 0.4% | May 29, 2026 | In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings |
| CVE-2026-49372 | HIGH | 7.5 | 0.3% | May 29, 2026 | In JetBrains TeamCity before 2026.1, 2025.11.5 unauthenticated SSRF via build status was possible |
| CVE-2026-49371 | HIGH | 8.2 | 0.3% | May 29, 2026 | In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible |
| CVE-2026-49370 | HIGH | 7.5 | 0.2% | May 29, 2026 | In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests |
| CVE-2026-49367 | HIGH | 8.8 | 0.3% | May 29, 2026 | In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account |
| CVE-2026-49366 | HIGH | 7.8 | 0.5% | May 29, 2026 | In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion |
| CVE-2026-47740 | HIGH | 8.1 | 0.3% | May 29, 2026 | Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Or... |
| CVE-2026-46372 | HIGH | 8.5 | 0.9% | May 29, 2026 | SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode... |
| CVE-2026-44648 | HIGH | 7.5 | 0.4% | May 29, 2026 | SillyTavern is a locally installed user interface that allows users to interact with text generation large language mode... |
| CVE-2026-42941 | HIGH | 8.7 | 0.2% | May 29, 2026 | The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password c... |
| CVE-2026-42929 | HIGH | 8.7 | 0.2% | May 29, 2026 | Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now