2026 CVE Vulnerabilities
50,941 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40172 | HIGH | 8.1 | 0.5% | May 22, 2026 | authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PAT... |
| CVE-2026-40166 | HIGH | 7.1 | 0.5% | May 22, 2026 | authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authent... |
| CVE-2026-39970 | HIGH | 8.5 | 0.3% | May 22, 2026 | TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain a critical stored XSS vulnerability in the app.type... |
| CVE-2026-39968 | HIGH | 7.1 | 0.3% | May 22, 2026 | TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("Credential Theft via ... |
| CVE-2026-46727 | HIGH | 8.1 | 0.5% | May 22, 2026 | An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getadd... |
| CVE-2026-39965 | HIGH | 7.7 | 0.2% | May 22, 2026 | TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain an SSRF via Open Redirect Bypass as the HTTP Reques... |
| CVE-2026-9255 | HIGH | 8.4 | 0.1% | May 22, 2026 | Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to ex... |
| CVE-2026-37470 | HIGH | 7.3 | 0.3% | May 22, 2026 | An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the Authentication interface, login p... |
| CVE-2026-36228 | HIGH | 7.3 | 0.4% | May 22, 2026 | Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execu... |
| CVE-2026-34207 | HIGH | 7.6 | 0.2% | May 22, 2026 | TypeBot is a chatbot builder tool. In versions prior to 3.16.0, SSRF protection for Webhook / HTTP Request blocks valida... |
| CVE-2026-28445 | HIGH | 8.7 | 0.3% | May 22, 2026 | Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the RatingButton component in the embed package renders... |
| CVE-2026-9047 | HIGH | 7.6 | 0.2% | May 22, 2026 | Improper handling of factor key state in the multi-factor authentication management feature in Devolutions Server allows... |
| CVE-2026-7325 | HIGH | 7.1 | 0.2% | May 22, 2026 | Improper authorization in the Active Directory browsing feature in Devolutions Server allows a low-privileged authentica... |
| CVE-2026-9256 | HIGH | 8.1 | 10.0% | May 22, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists w... |
| CVE-2026-8992 | HIGH | 8.8 | 0.6% | May 22, 2026 | An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenti... |
| CVE-2026-9277 | HIGH | 8.1 | 0.8% | May 22, 2026 | shell-quote's `quote()` function did not validate object-token inputs against the operator model used by `parse()`. The ... |
| CVE-2026-8671 | HIGH | 7.5 | 0.2% | May 22, 2026 | Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows R... |
| CVE-2026-44417 | HIGH | 7.5 | 0.6% | May 22, 2026 | The fix for CVE-2025-48913: Apache CXF: Untrusted JMS configuration can lead to RCE was not complete, meaning that anoth... |
| CVE-2026-5740 | HIGH | 7.5 | 0.3% | May 22, 2026 | Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to properly validate ... |
| CVE-2026-5308 | HIGH | 7.5 | 0.3% | May 22, 2026 | Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to enforce request bo... |
| CVE-2026-3473 | HIGH | 7.1 | 0.1% | May 22, 2026 | Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file owne... |
| CVE-2026-25606 | HIGH | 8.7 | 0.2% | May 22, 2026 | A SQL injection vulnerability has been identified in STER. Improper neutralization of input provided by user into multip... |
| CVE-2026-9011 | HIGH | 7.5 | 0.4% | May 22, 2026 | The Ditty – Responsive News Tickers, Sliders, and Lists plugin for WordPress is vulnerable to authorization bypass in al... |
| CVE-2026-8679 | HIGH | 7.5 | 1.5% | May 22, 2026 | The AudioIgniter plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including... |
| CVE-2026-9018 | HIGH | 8.8 | 0.5% | May 22, 2026 | The Easy Elements for Elementor – Addons & Website Templates plugin for WordPress is vulnerable to Privilege Escalation ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now