2026 CVE Vulnerabilities
50,938 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42013 | HIGH | 8.2 | 0.4% | May 26, 2026 | A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the va... |
| CVE-2026-42012 | HIGH | 7.1 | 0.4% | May 26, 2026 | A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certifi... |
| CVE-2026-9580 | HIGH | 7.3 | 0.3% | May 26, 2026 | A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepa... |
| CVE-2026-8676 | HIGH | 8.8 | 0.2% | May 26, 2026 | An attacker is able to downgrade the security of a Bluetooth LE connection by deleting an existing bond, spoofing the bo... |
| CVE-2026-45575 | HIGH | 7.4 | 0.1% | May 26, 2026 | epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who ... |
| CVE-2026-44847 | HIGH | 7.5 | 0.3% | May 26, 2026 | MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoint (/api/trigger/v1/w... |
| CVE-2026-44843 | HIGH | 8.2 | 0.4% | May 26, 2026 | LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains... |
| CVE-2026-44837 | HIGH | 7.5 | 0.4% | May 26, 2026 | view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3... |
| CVE-2026-44209 | HIGH | 7.5 | 0.5% | May 26, 2026 | Banks generates meaningful LLM prompts using a template language that makes sense. Prior to 2.4.2, banks uses jinja2.Env... |
| CVE-2026-9575 | HIGH | 7.3 | 0.3% | May 26, 2026 | A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0. This issue affects some unknown... |
| CVE-2026-9574 | HIGH | 7.3 | 0.3% | May 26, 2026 | A flaw has been found in itsourcecode Student Transcript Processing System 1.0. This vulnerability affects unknown code ... |
| CVE-2026-9573 | HIGH | 7.3 | 0.3% | May 26, 2026 | A vulnerability was detected in itsourcecode Student Transcript Processing System 1.0. This affects an unknown part of t... |
| CVE-2026-44833 | HIGH | 7.1 | 0.2% | May 26, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows att... |
| CVE-2026-44832 | HIGH | 8.8 | 0.3% | May 26, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permissio... |
| CVE-2026-8890 | HIGH | 8.8 | 0.5% | May 26, 2026 | code100x contains an authentication bypass vulnerability in the Mobile API that allows unauthenticated attackers to impe... |
| CVE-2026-4051 | HIGH | 7.2 | 0.4% | May 26, 2026 | IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an attacker with administrative privileges to e... |
| CVE-2026-3603 | HIGH | 7.1 | 0.4% | May 26, 2026 | IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through Interim Fix 021, 7.1.0 Interim Fix 001 through Int... |
| CVE-2026-9560 | HIGH | 7.8 | 0.6% | May 26, 2026 | Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute ... |
| CVE-2026-8854 | HIGH | 7.5 | 0.4% | May 26, 2026 | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_mem_cache. |
| CVE-2026-8835 | HIGH | 7.3 | 0.3% | May 26, 2026 | IBM HTTP Server 8.5, and 9.0 is vulnerable to invalid pointer dereference. A privileged user, authenticated to the Admin... |
| CVE-2026-8834 | HIGH | 8 | 0.3% | May 26, 2026 | IBM HTTP Server 8.5, and 9.0 contains a buffer overflow vulnerability. A privileged user, authenticated to the Administr... |
| CVE-2026-8620 | HIGH | 7.5 | 0.3% | May 26, 2026 | IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server... |
| CVE-2026-7454 | HIGH | 7.8 | 0.1% | May 26, 2026 | A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A mal... |
| CVE-2026-7452 | HIGH | 7.8 | 0.2% | May 26, 2026 | A maliciously crafted WRL file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A mal... |
| CVE-2026-7451 | HIGH | 7.8 | 0.2% | May 26, 2026 | A maliciously crafted TIF file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now