2026 CVE Vulnerabilities
50,938 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39661 | HIGH | 7.5 | 0.4% | May 26, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-25713 | HIGH | 7.8 | 0.2% | May 26, 2026 | MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerability |
| CVE-2026-25104 | HIGH | 7.8 | 0.2% | May 26, 2026 | MediaArea MediaInfoLib LXF parsing heap-based buffer overflow vulnerability |
| CVE-2026-8047 | HIGH | 8.7 | 0.4% | May 26, 2026 | The affected products perform improper length checking when parsing incoming HTTP requests, resulting in a size-limited ... |
| CVE-2026-8046 | HIGH | 8.1 | 0.3% | May 26, 2026 | The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged ... |
| CVE-2026-44469 | HIGH | 7 | 0.1% | May 26, 2026 | The affected product extracts installation files to a temporary directory with incorrect default permissions during admi... |
| CVE-2026-44468 | HIGH | 8.5 | 0.1% | May 26, 2026 | The affected product creates a directory with insecure default permissions during administrative installation. This allo... |
| CVE-2026-9496 | HIGH | 7.7 | 0.3% | May 26, 2026 | Versions of the package pacote from 11.2.7 and before 21.5.1 are vulnerable to Denial of Service (DoS) via the addGitSha... |
| CVE-2026-9495 | HIGH | 7.3 | 0.4% | May 26, 2026 | Versions of the package @koa/router from 14.0.0 and before 15.0.0 are vulnerable to Access Control Bypass due to the mid... |
| CVE-2026-9528 | HIGH | 7.3 | 0.3% | May 26, 2026 | A vulnerability was identified in itsourcecode Electronic Judging System 1.0. Impacted is an unknown function of the fil... |
| CVE-2026-9526 | HIGH | 7.3 | 0.3% | May 26, 2026 | A vulnerability was found in itsourcecode Electronic Judging System 1.0. This vulnerability affects unknown code of the ... |
| CVE-2026-9525 | HIGH | 7.3 | 0.3% | May 26, 2026 | A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /... |
| CVE-2026-9523 | HIGH | 7.3 | 0.3% | May 26, 2026 | A vulnerability was detected in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 3000WEBV... |
| CVE-2026-9538 | HIGH | 7.5 | 0.4% | May 26, 2026 | Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar heade... |
| CVE-2026-9521 | HIGH | 7.3 | 0.4% | May 26, 2026 | A security vulnerability has been detected in fraillt bitsery up to 5.2.4. Affected is the function loadFromSharedState ... |
| CVE-2026-42497 | HIGH | 7.5 | 0.4% | May 26, 2026 | Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directo... |
| CVE-2026-9517 | HIGH | 7.3 | 0.4% | May 26, 2026 | A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown fun... |
| CVE-2026-48837 | HIGH | 8.5 | 0.4% | May 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements... |
| CVE-2026-45438 | HIGH | 7.5 | 0.3% | May 25, 2026 | Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Incorrectly Configured ... |
| CVE-2026-45216 | HIGH | 8.8 | 0.4% | May 25, 2026 | Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation. This issue affects... |
| CVE-2026-45209 | HIGH | 7.5 | 0.3% | May 25, 2026 | Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrectly Configured Access... |
| CVE-2026-39436 | HIGH | 7.1 | 0.1% | May 25, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in bgermann CformsII allows Cross Site Request Forgery. This issue affe... |
| CVE-2026-24937 | HIGH | 7.2 | 0.4% | May 25, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in VideoWhisper.Com Broadcast Live Video allows ... |
| CVE-2026-48848 | HIGH | 7.2 | 0.4% | May 25, 2026 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascadi... |
| CVE-2026-48844 | HIGH | 7.5 | 0.4% | May 25, 2026 | Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues o... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now