2026 CVE Vulnerabilities
49,638 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44698 | HIGH | 8.3 | 0.1% | May 29, 2026 | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for ... |
| CVE-2026-44239 | HIGH | 8.8 | 0.3% | May 29, 2026 | FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes P... |
| CVE-2026-44238 | HIGH | 8.8 | 0.3% | May 29, 2026 | FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through... |
| CVE-2026-44237 | HIGH | 8.1 | 0.2% | May 29, 2026 | FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently ... |
| CVE-2026-40528 | HIGH | 7.8 | 0.1% | May 29, 2026 | OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_valu... |
| CVE-2026-10073 | HIGH | 8.7 | 0.4% | May 29, 2026 | DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing unauthenticated local attackers to ... |
| CVE-2026-10072 | HIGH | 8.6 | 0.5% | May 29, 2026 | DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to up... |
| CVE-2026-9509 | HIGH | 8.7 | 0.4% | May 29, 2026 | An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated... |
| CVE-2026-48527 | HIGH | 8.7 | 0.2% | May 29, 2026 | HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up to and including 26.0.0 are affected by... |
| CVE-2026-9809 | HIGH | 7.6 | 0.2% | May 29, 2026 | A stored Cross-Site Scripting (XSS) vulnerability exists in the Projects component of Mautic 7. When displaying project ... |
| CVE-2026-9808 | HIGH | 7.1 | 0.2% | May 29, 2026 | An authorization bypass vulnerability exists in the Mautic 7 API v2 endpoints (utilizing API Platform). Under certain co... |
| CVE-2026-46579 | HIGH | 7.5 | 0.4% | May 29, 2026 | A flaw was found in the OpenShift Router. When a Route has `insecureEdgeTerminationPolicy` set to Allow, the HTTP fronte... |
| CVE-2026-6075 | HIGH | 8.1 | 0.2% | May 29, 2026 | The Media Library Assistant plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and incl... |
| CVE-2026-49196 | HIGH | 7.2 | 0.4% | May 29, 2026 | The Wi-Fi device blocking feature fails to sanitize MAC address input, allowing injection and execution of arbitrary she... |
| CVE-2026-49195 | HIGH | 8.8 | 0.2% | May 29, 2026 | Unauthenticated Debug Service. The /sbin/mtk_dut binary is exposed on TCP port 9000 without authentication, allowing any... |
| CVE-2026-10056 | HIGH | 7.5 | 0.2% | May 29, 2026 | CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default ... |
| CVE-2026-4776 | HIGH | 7.1 | 0.2% | May 29, 2026 | An SQL injection vulnerability exists in Mautic's API contact filtering mechanism. Due to insufficient recursive sanitiz... |
| CVE-2026-9493 | HIGH | 7.1 | 0.3% | May 29, 2026 | Service Center developed by BankPro E-Service Technology has an Insecure Direct Object Reference vulnerability, allowing... |
| CVE-2026-8070 | HIGH | 7.3 | 0.1% | May 29, 2026 | Incorrect permission assignment for a critical resource in Armoury Crate allows a local user to bypass the driver’s vali... |
| CVE-2026-7480 | HIGH | 7.3 | 0.1% | May 29, 2026 | An Incorrect Permission Assignment for Critical Resource vulnerability in ASUS System Control Interface allows a local u... |
| CVE-2026-9999 | HIGH | 8.8 | 0.2% | May 28, 2026 | Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execu... |
| CVE-2026-9998 | HIGH | 8.3 | 0.2% | May 28, 2026 | Integer overflow in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the rend... |
| CVE-2026-9997 | HIGH | 8.3 | 0.2% | May 28, 2026 | Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the rende... |
| CVE-2026-9995 | HIGH | 8.8 | 0.3% | May 28, 2026 | Use after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-9994 | HIGH | 8.3 | 0.2% | May 28, 2026 | Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now