2026 CVE Vulnerabilities
50,000 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44322 | HIGH | 7.5 | 0.4% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF PATCH /3gpp-pfd-managemen... |
| CVE-2026-44321 | HIGH | 7.5 | 0.4% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's SMF mounts the UPI management... |
| CVE-2026-44320 | HIGH | 7.3 | 0.2% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-callback ... |
| CVE-2026-44319 | HIGH | 7.5 | 0.4% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF terminates the entire pro... |
| CVE-2026-44316 | HIGH | 7.5 | 0.4% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's PCF POST /npcf-smpolicycontro... |
| CVE-2026-42790 | HIGH | 8.1 | 0.3% | May 27, 2026 | Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS... |
| CVE-2026-42459 | HIGH | 7.5 | 0.3% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the free5GC UDM component fails to vali... |
| CVE-2026-42083 | HIGH | 8.2 | 0.3% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, PCF Npcf_SMPolicyControl missing authen... |
| CVE-2026-42081 | HIGH | 7.1 | 0.3% | May 27, 2026 | free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not verify the ... |
| CVE-2026-38945 | HIGH | 7.8 | 0.8% | May 27, 2026 | Command injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute arbitrary cod... |
| CVE-2026-49046 | HIGH | 8.5 | 0.3% | May 27, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arjun Thakur Dupli... |
| CVE-2026-48922 | HIGH | 7.5 | 0.4% | May 27, 2026 | Jenkins Credentials Binding Plugin 720.v3f6decef43ea_ and earlier does not properly sanitize file names for file and zip... |
| CVE-2026-48921 | HIGH | 7.5 | 0.3% | May 27, 2026 | Jenkins Pipeline: Groovy Libraries Plugin 797.v90ea_a_9b_e45a_0 and earlier does not prohibit symbolic links in shared l... |
| CVE-2026-48920 | HIGH | 8.8 | 0.3% | May 27, 2026 | Jenkins Email Extension Plugin 1933.v45cec755423f and earlier allows inlining images as `base64` in email content by set... |
| CVE-2026-48544 | HIGH | 8.7 | 0.4% | May 27, 2026 | Taipy 4.1.1, fixed in commit 129fd40, contains a path traversal vulnerability in the ElementLibrary.get_resource() metho... |
| CVE-2026-47118 | HIGH | 7.1 | 0.4% | May 27, 2026 | Agent Zero before version 1.15 contains a path traversal vulnerability that allows unauthenticated attackers to read arb... |
| CVE-2026-45022 | HIGH | 7.5 | 0.2% | May 27, 2026 | go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may par... |
| CVE-2026-44988 | HIGH | 8.8 | 0.2% | May 27, 2026 | LibVNCClient is a library for easy implementation of a VNC client. In 0.9.15 and earlier, LibVNCClient's Tight encoding ... |
| CVE-2026-44971 | HIGH | 8.2 | 0.2% | May 27, 2026 | GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0, the programmatic remote project scannin... |
| CVE-2026-44902 | HIGH | 7.5 | 0.5% | May 27, 2026 | opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 0.217.0, a single malformed HTTP request crashes any N... |
| CVE-2026-44838 | HIGH | 8.1 | 0.3% | May 27, 2026 | RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin allows for topic-level ... |
| CVE-2026-44830 | HIGH | 8.7 | 0.2% | May 27, 2026 | Nocturne Memory is a lightweight, rollbackable, and visual Long-Term Memory Server for MCP Agents. Prior to 2.4.1, when ... |
| CVE-2026-42280 | HIGH | 7.1 | 0.2% | May 27, 2026 | Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.j... |
| CVE-2026-42184 | HIGH | 8.8 | 0.3% | May 27, 2026 | Tauri is a framework for building binaries for all major desktop platforms. From 2.0 to 2.11.0, a flaw in Tauri's is_loc... |
| CVE-2026-37713 | HIGH | 7.3 | 0.4% | May 27, 2026 | An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now