2026 CVE Vulnerabilities
50,954 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44066 | HIGH | 7.1 | 0.3% | May 21, 2026 | Multiple heap out-of-bounds reads in the Spotlight RPC unmarshalling code in Netatalk 3.1.0 through 4.4.2 allow a remote... |
| CVE-2026-44064 | HIGH | 7.1 | 0.2% | May 21, 2026 | An out-of-bounds read in ASP session ID handling in Netatalk 1.3 through 4.4.2 allows an adjacent network attacker to ob... |
| CVE-2026-44062 | HIGH | 7.5 | 0.4% | May 21, 2026 | A missing output length bounds check in pull_charset_flags() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticat... |
| CVE-2026-44060 | HIGH | 7.5 | 0.3% | May 21, 2026 | An integer underflow in dsi_writeinit() in Netatalk 1.5.0 through 4.4.2 allows a remote unauthenticated attacker to caus... |
| CVE-2026-44058 | HIGH | 7.2 | 0.5% | May 21, 2026 | An authentication bypass vulnerability in Netatalk 2.2.2 through 4.4.2 allows a remote privileged user to authenticate a... |
| CVE-2026-44055 | HIGH | 7.5 | 0.4% | May 21, 2026 | A logic error involving bitwise OR operations in Netatalk 3.1.4 through 4.4.2 allows a remote authenticated attacker to ... |
| CVE-2026-44053 | HIGH | 7.4 | 0.3% | May 21, 2026 | Netatalk 1.5.0 through 4.2.2 uses a broken cryptographic algorithm in the DHCAST128 UAM, which allows a remote attacker ... |
| CVE-2026-44052 | HIGH | 7.5 | 0.2% | May 21, 2026 | Netatalk 2.1.0 through 4.4.2 inserts LDAP simple-bind passwords into log output in cleartext, which allows an attacker w... |
| CVE-2026-44051 | HIGH | 8.1 | 0.5% | May 21, 2026 | An improper link resolution vulnerability in Netatalk 3.0.2 through 4.4.2 allows a remote authenticated attacker to read... |
| CVE-2026-44049 | HIGH | 7.5 | 0.5% | May 21, 2026 | An out-of-bounds write due to improper null termination in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a re... |
| CVE-2026-44048 | HIGH | 8.8 | 0.4% | May 21, 2026 | A stack-based buffer overflow via UCS-2 type confusion in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a rem... |
| CVE-2026-44047 | HIGH | 8.8 | 0.4% | May 21, 2026 | An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 through 4.4.2 allows a remote authenticated a... |
| CVE-2026-40165 | HIGH | 8.7 | 0.5% | May 21, 2026 | authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 ... |
| CVE-2026-40092 | HIGH | 7.5 | 0.6% | May 20, 2026 | nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and below, a malic... |
| CVE-2026-8632 | HIGH | 7.8 | 0.9% | May 20, 2026 | A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vul... |
| CVE-2026-47373 | HIGH | 7.5 | 0.4% | May 20, 2026 | Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks. These versions use Perl's built-in e... |
| CVE-2026-9144 | HIGH | 8.4 | 0.4% | May 20, 2026 | Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a stored cross-site scripting vulnerability in the embedde... |
| CVE-2026-9137 | HIGH | 7.5 | 0.4% | May 20, 2026 | The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB ... |
| CVE-2026-9133 | HIGH | 8.3 | 0.3% | May 20, 2026 | Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws... |
| CVE-2026-9126 | HIGH | 8.8 | 0.4% | May 20, 2026 | Use after free in DOM in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code in... |
| CVE-2026-9123 | HIGH | 7.5 | 0.2% | May 20, 2026 | Heap buffer overflow in Chromecast in Google Chrome on Android, Linux, ChromeOS prior to 148.0.7778.179 allowed a local ... |
| CVE-2026-9121 | HIGH | 8.8 | 0.3% | May 20, 2026 | Out of bounds read in GPU in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to potentially exploit h... |
| CVE-2026-9120 | HIGH | 8.8 | 0.5% | May 20, 2026 | Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code vi... |
| CVE-2026-9119 | HIGH | 8.8 | 0.5% | May 20, 2026 | Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrar... |
| CVE-2026-9118 | HIGH | 8.8 | 0.4% | May 20, 2026 | Use after free in XR in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now