2026 CVE Vulnerabilities
49,638 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6824 | HIGH | 8.4 | 0.4% | May 29, 2026 | A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitiza... |
| CVE-2026-5768 | HIGH | 8.8 | 0.3% | May 29, 2026 | The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing p... |
| CVE-2026-47179 | HIGH | 7.7 | 0.3% | May 29, 2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.Ge... |
| CVE-2026-47125 | HIGH | 8.8 | 0.2% | May 29, 2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.2, the PUT /api/envi... |
| CVE-2026-45627 | HIGH | 8.2 | 0.2% | May 29, 2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.0, the unauthenticat... |
| CVE-2026-44697 | HIGH | 8.6 | 0.4% | May 29, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-... |
| CVE-2026-10108 | HIGH | 8.7 | 0.5% | May 29, 2026 | xiaomusic v0.5.7 contains an unauthenticated path traversal vulnerability in the GET /music/{file_path:path} endpoint th... |
| CVE-2026-10107 | HIGH | 7.7 | 0.3% | May 29, 2026 | MoviePilot v2 contains a server-side request forgery vulnerability in the image proxy endpoint that allows authenticated... |
| CVE-2026-10105 | HIGH | 8.7 | 0.3% | May 29, 2026 | agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inj... |
| CVE-2026-45662 | HIGH | 8.8 | 0.8% | May 29, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.0 and earlier, the deleteRegistry function in Dok... |
| CVE-2026-39276 | HIGH | 7.2 | 0.8% | May 29, 2026 | The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrator... |
| CVE-2026-35674 | HIGH | 8.8 | 0.3% | May 29, 2026 | OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped client... |
| CVE-2026-35630 | HIGH | 8 | 0.2% | May 29, 2026 | OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to ... |
| CVE-2026-32905 | HIGH | 8.7 | 0.2% | May 29, 2026 | OpenClaw before 2026.5.4 contains an authorization bypass vulnerability in the bundled device-pair plugin that allows no... |
| CVE-2026-10069 | HIGH | 8.7 | 0.4% | May 29, 2026 | A vulnerability has been found in Shibby Tomato 1.28. The impacted element is an unknown function of the file usr/sbin/m... |
| CVE-2026-10068 | HIGH | 7.3 | 0.3% | May 29, 2026 | A flaw has been found in Shibby Tomato 1.28. The affected element is the function send of the file usr/sbin/miniupnpd of... |
| CVE-2026-10067 | HIGH | 8.8 | 0.4% | May 29, 2026 | A vulnerability was detected in Shibby Tomato 1.28. Impacted is the function sub_90F0 of the file multimon.cgi. The mani... |
| CVE-2026-10066 | HIGH | 8.8 | 0.4% | May 29, 2026 | A security vulnerability has been detected in Shibby Tomato up to 1.28. This issue affects the function sub_9068 of the ... |
| CVE-2026-10065 | HIGH | 8.8 | 0.4% | May 29, 2026 | A weakness has been identified in Shibby Tomato 1.28. This vulnerability affects the function get_ups_field of the file ... |
| CVE-2026-39292 | HIGH | 7.3 | 0.5% | May 29, 2026 | Falco Solutions PHPPageBuilder v0.31.0 contains an unrestricted file upload vulnerability in the pagemanager/pagebuilder... |
| CVE-2026-46510 | HIGH | 8.2 | 0.3% | May 29, 2026 | form-data-objectizer converts FormData to object. Prior to 1.0.1, form-data-objectizer walks bracket-notation form keys ... |
| CVE-2026-45707 | HIGH | 8.1 | 0.2% | May 29, 2026 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior... |
| CVE-2026-45615 | HIGH | 8.2 | 0.2% | May 29, 2026 | mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decod... |
| CVE-2026-45578 | HIGH | 8.8 | 0.3% | May 29, 2026 | WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The... |
| CVE-2026-45555 | HIGH | 7.8 | 0.1% | May 29, 2026 | Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now