2026 CVE Vulnerabilities
50,938 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45728 | HIGH | 7.5 | 0.3% | May 26, 2026 | Algernon is a small self-contained pure-Go web server. Prior to 1.17.7, when Algernon is invoked with a single file path... |
| CVE-2026-44729 | HIGH | 8.7 | 0.3% | May 26, 2026 | Twenty is an open source CRM. In 1.18.0 and earlier, the file serving endpoints in Twenty CRM at /files/* and /file/:fil... |
| CVE-2026-44680 | HIGH | 7.6 | 1.3% | May 26, 2026 | MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to @mikro-o... |
| CVE-2026-43982 | HIGH | 8.7 | 0.3% | May 26, 2026 | Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, uploadedFileSaveIn() in lua/upload/upload.go use... |
| CVE-2026-43981 | HIGH | 8.2 | 0.2% | May 26, 2026 | Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, in engine/luahandler.go, the sync.RWMutex protec... |
| CVE-2026-40384 | HIGH | 7.5 | 0.4% | May 26, 2026 | An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerabili... |
| CVE-2026-24162 | HIGH | 7.8 | 0.4% | May 26, 2026 | NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of unt... |
| CVE-2026-48692 | HIGH | 8.1 | 0.2% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 exposes a gRPC API server on port 50052 with no authentication mechanism. The... |
| CVE-2026-48688 | HIGH | 7.5 | 0.3% | May 26, 2026 | FastNetMon Community Edition through 1.2.9 contains multiple out-of-bounds reads in the BGP MP_REACH_NLRI IPv6 attribute... |
| CVE-2026-43935 | HIGH | 8.1 | 0.3% | May 26, 2026 | e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset p... |
| CVE-2026-25112 | HIGH | 7.8 | 0.1% | May 26, 2026 | A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack. |
| CVE-2026-9552 | HIGH | 7.3 | 0.3% | May 26, 2026 | A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2.0. This vulnerability affects unknown c... |
| CVE-2026-9551 | HIGH | 7.3 | 0.3% | May 26, 2026 | A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. This affects the function xp_cmdshell of ... |
| CVE-2026-9550 | HIGH | 7.3 | 0.5% | May 26, 2026 | A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0.... |
| CVE-2026-46368 | HIGH | 8.8 | 6.6% | May 26, 2026 | luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distribu... |
| CVE-2026-45082 | HIGH | 7.6 | 0.3% | May 26, 2026 | Karakeep is a elf-hostable bookmark-everything app. A Server-Side Request Forgery (SSRF) protection bypass vulnerability... |
| CVE-2026-42785 | HIGH | 8.6 | 0.7% | May 26, 2026 | OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitra... |
| CVE-2026-42425 | HIGH | 8.6 | 0.6% | May 26, 2026 | OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticated administrative users to exe... |
| CVE-2026-41401 | HIGH | 7.1 | 0.5% | May 26, 2026 | libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly up... |
| CVE-2026-40034 | HIGH | 8.5 | 0.4% | May 26, 2026 | gix-submodule before 0.29.0 (gitoxide before 0.5.21, gix before 0.84.0) incorrectly validates the update field in .gitmo... |
| CVE-2026-40033 | HIGH | 8.8 | 0.9% | May 26, 2026 | FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers t... |
| CVE-2026-9544 | HIGH | 7.3 | 0.3% | May 26, 2026 | A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10. Affected by thi... |
| CVE-2026-48133 | HIGH | 7.5 | 4.8% | May 26, 2026 | When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to r... |
| CVE-2026-48132 | HIGH | 8.1 | 2.1% | May 26, 2026 | The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As... |
| CVE-2026-48131 | HIGH | 8.1 | 2.7% | May 26, 2026 | The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage o... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now