2026 CVE Vulnerabilities
50,000 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47269 | HIGH | 7.4 | 0.3% | May 27, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, pam_usb's deny_remot... |
| CVE-2026-45137 | HIGH | 8.2 | 0.2% | May 27, 2026 | Anchor is a framework providing several convenient developer tools for writing Solana programs. From 1.0.0 to before 1.0... |
| CVE-2026-45136 | HIGH | 7.8 | 0.2% | May 27, 2026 | claude-code-cache-fix is a cache optimization proxy for Claude Code. From 3.5.0 to before 3.5.2, tools/quota-statusline.... |
| CVE-2026-44713 | HIGH | 8.8 | 0.2% | May 27, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, src/tmux.c reads the ... |
| CVE-2026-44712 | HIGH | 8.2 | 0.2% | May 27, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, a crafted UUID such a... |
| CVE-2026-44711 | HIGH | 7.9 | 0.2% | May 27, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, symlink attacks on pa... |
| CVE-2026-44709 | HIGH | 7.8 | 0.2% | May 27, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, pamusb-pinentry reads... |
| CVE-2026-44660 | HIGH | 7.5 | 0.4% | May 27, 2026 | UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.12.1, when ujso... |
| CVE-2026-8361 | HIGH | 7.5 | 0.4% | May 27, 2026 | A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processing a URL path starting with /woshome |
| CVE-2026-8360 | HIGH | 7.5 | 0.3% | May 27, 2026 | Function calls to WOSCommonUtil.dll!WOSSysInfoGetDeviceInterface() in various DLLs (i.e., WOSProfileMgrModule.dll, WOSWe... |
| CVE-2026-8359 | HIGH | 7.5 | 0.3% | May 27, 2026 | When processing a request with a URL path starting with /status or /sysinfo, WOSHttpStatusModule.dll is to be loaded to ... |
| CVE-2026-48064 | HIGH | 8.1 | 0.3% | May 27, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, when a PAM service is... |
| CVE-2026-47272 | HIGH | 7.1 | 0.1% | May 27, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.0, the pusb_pad_compare(... |
| CVE-2026-47161 | HIGH | 8.7 | 0.5% | May 27, 2026 | RELATE is a web-based courseware package. Prior to commit d66ba5659b459bf1ba56b7109b5f9ecf197cbefb, RELATE LMS configure... |
| CVE-2026-45134 | HIGH | 7.1 | 0.2% | May 27, 2026 | LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and... |
| CVE-2026-45108 | HIGH | 8.4 | 0.2% | May 27, 2026 | Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 2.0.0 to before 3.1.5 and 2.3.11, ... |
| CVE-2026-45104 | HIGH | 7.5 | 0.3% | May 27, 2026 | MapServer is a system for developing web-based GIS applications. From 6.4.0 to before 8.6.3, msSLDParseUserStyle always ... |
| CVE-2026-44886 | HIGH | 8.7 | 0.2% | May 27, 2026 | Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. From 2024-06-29 to before 2026-05-07, the web ap... |
| CVE-2026-44724 | HIGH | 7.8 | 0.6% | May 27, 2026 | systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation... |
| CVE-2026-42197 | HIGH | 8.7 | 0.3% | May 27, 2026 | RELATE is a web-based courseware package. Versions prior to commit 555f0efb1c5bd7531c07cd73724d7e566a81f620 have a store... |
| CVE-2026-4868 | HIGH | 8.2 | 0.3% | May 27, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 1... |
| CVE-2026-44635 | HIGH | 7.5 | 0.4% | May 27, 2026 | Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, DefaultQueryCompiler.visitJSONPathLeg does n... |
| CVE-2026-5509 | HIGH | 7.2 | 2.5% | May 27, 2026 | An authenticated command injection vulnerability exists in the Archer BE450 v1 and BE7200 v1 router that allows an admin... |
| CVE-2026-48153 | HIGH | 8.5 | 0.2% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.39.0, fetchToken in the OAuth2 SDK makes a POST to a builder-su... |
| CVE-2026-48152 | HIGH | 8.1 | 0.3% | May 27, 2026 | Budibase is an open-source low-code platform. Prior to 3.39.0, the single-datasource GET and PUT routes are guarded by g... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now