2026 CVE Vulnerabilities
50,937 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24196 | HIGH | 7.1 | 0.2% | May 26, 2026 | NVIDIA Display Driver for Linux contains a vulnerability where a user could cause an out-of-bounds read. A successful ex... |
| CVE-2026-24194 | HIGH | 7.8 | 0.2% | May 26, 2026 | NVIDIA Display Driver for Linux contains a vulnerability in a kernel mode layer handler, where a user could cause improp... |
| CVE-2026-24193 | HIGH | 7.8 | 0.2% | May 26, 2026 | NVIDIA Display Driver for Windows and Linux contains a vulnerability where an attacker could cause an out-of-bounds writ... |
| CVE-2026-24192 | HIGH | 7.8 | 0.2% | May 26, 2026 | NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause an incorrect conversion between n... |
| CVE-2026-24191 | HIGH | 7.8 | 0.1% | May 26, 2026 | NVIDIA Display Driver for Windows contains a vulnerability where an attacker could cause a time-of-check time-of-use iss... |
| CVE-2026-24190 | HIGH | 7.8 | 0.2% | May 26, 2026 | NVIDIA Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer, where a user could cause ... |
| CVE-2026-24187 | HIGH | 8.8 | 0.2% | May 26, 2026 | NVIDIA Display Driver for Linux contains a vulnerability where an attacker could cause a use-after-free. A successful ex... |
| CVE-2026-9562 | HIGH | 7.3 | 0.3% | May 26, 2026 | A vulnerability has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Th... |
| CVE-2026-8852 | HIGH | 7.5 | 0.2% | May 26, 2026 | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_fastcgi module. |
| CVE-2026-8850 | HIGH | 7.5 | 0.4% | May 26, 2026 | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_upload. |
| CVE-2026-48901 | HIGH | 7.5 | 0.2% | May 26, 2026 | The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key. |
| CVE-2026-48897 | HIGH | 7.5 | 0.2% | May 26, 2026 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. |
| CVE-2026-48896 | HIGH | 7.5 | 0.3% | May 26, 2026 | Insufficient state checks lead to a vector that allows to bypass 2FA checks. |
| CVE-2026-48864 | HIGH | 7.8 | 0.2% | May 26, 2026 | A flaw was found in libsolv. This heap buffer overflow occurs during the decompression of attacker-controlled compressed... |
| CVE-2026-48697 | HIGH | 7.4 | 0.2% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 does not verify TLS certificates on outbound HTTPS connections. The execute_w... |
| CVE-2026-48690 | HIGH | 7.1 | 0.1% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 contains an integer overflow vulnerability in the packet capture buffer alloc... |
| CVE-2026-48126 | HIGH | 8.2 | 0.3% | May 26, 2026 | Algernon is a small self-contained pure-Go web server. Prior to 1.17.8, when algernon is started with --domain (or --let... |
| CVE-2026-45728 | HIGH | 7.5 | 0.3% | May 26, 2026 | Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path... |
| CVE-2026-44729 | HIGH | 8.7 | 0.3% | May 26, 2026 | Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fil... |
| CVE-2026-44680 | HIGH | 7.6 | 1.3% | May 26, 2026 | MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to @mikro-o... |
| CVE-2026-43982 | HIGH | 8.7 | 0.3% | May 26, 2026 | Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, uploadedFileSaveIn() in lua/upload/upload.go use... |
| CVE-2026-43981 | HIGH | 8.2 | 0.2% | May 26, 2026 | Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, in engine/luahandler.go, the sync.RWMutex protec... |
| CVE-2026-40384 | HIGH | 7.5 | 0.4% | May 26, 2026 | An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerabili... |
| CVE-2026-24162 | HIGH | 7.8 | 0.4% | May 26, 2026 | NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of unt... |
| CVE-2026-48692 | HIGH | 8.1 | 0.2% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now