2026 CVE Vulnerabilities
50,911 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9628 | HIGH | 8.8 | 0.5% | May 27, 2026 | A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is an unknown function of the file /gofo... |
| CVE-2026-9627 | HIGH | 8.8 | 0.5% | May 27, 2026 | A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file... |
| CVE-2026-9207 | HIGH | 8.8 | 0.4% | May 27, 2026 | Tanium addressed an unauthorized code execution vulnerability in Connect. |
| CVE-2026-9156 | HIGH | 7.5 | 0.2% | May 27, 2026 | Tanium addressed a denial of service vulnerability in Tanium Server. |
| CVE-2026-49017 | HIGH | 7.1 | 0.3% | May 27, 2026 | In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-ch... |
| CVE-2026-49014 | HIGH | 7.8 | 0.1% | May 27, 2026 | In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buf... |
| CVE-2026-9606 | HIGH | 7.3 | 0.3% | May 27, 2026 | A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the fil... |
| CVE-2026-9605 | HIGH | 7.3 | 0.3% | May 27, 2026 | A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c ... |
| CVE-2026-9312 | HIGH | 8.2 | 6.6% | May 27, 2026 | A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenti... |
| CVE-2026-9584 | HIGH | 7.3 | 0.3% | May 26, 2026 | A security vulnerability has been detected in code-projects Project Management System 1.0. Affected is an unknown functi... |
| CVE-2026-5260 | HIGH | 8.2 | 0.7% | May 26, 2026 | A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key excha... |
| CVE-2026-45574 | HIGH | 8.1 | 0.1% | May 26, 2026 | epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on t... |
| CVE-2026-45298 | HIGH | 8.6 | 1.5% | May 26, 2026 | Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quick... |
| CVE-2026-44983 | HIGH | 7.3 | 0.2% | May 26, 2026 | smallbitvec is a growable bit-vector for Rust, optimized for size. From 1.0.1 to 2.6.0, an integer overflow in the inter... |
| CVE-2026-44905 | HIGH | 7.5 | 0.2% | May 26, 2026 | Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vul... |
| CVE-2026-44900 | HIGH | 8.1 | 0.1% | May 26, 2026 | epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.1, in SignedPublic... |
| CVE-2026-43988 | HIGH | 7.5 | 0.2% | May 26, 2026 | Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vul... |
| CVE-2026-42013 | HIGH | 8.2 | 0.4% | May 26, 2026 | A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the va... |
| CVE-2026-42012 | HIGH | 7.1 | 0.4% | May 26, 2026 | A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certifi... |
| CVE-2026-9580 | HIGH | 7.3 | 0.3% | May 26, 2026 | A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepa... |
| CVE-2026-8676 | HIGH | 8.8 | 0.2% | May 26, 2026 | An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bo... |
| CVE-2026-45575 | HIGH | 7.4 | 0.1% | May 26, 2026 | epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who ... |
| CVE-2026-44847 | HIGH | 7.5 | 0.3% | May 26, 2026 | MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoint (/api/trigger/v1/w... |
| CVE-2026-44843 | HIGH | 8.2 | 0.4% | May 26, 2026 | LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains... |
| CVE-2026-44837 | HIGH | 7.5 | 0.4% | May 26, 2026 | view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now