2026 CVE Vulnerabilities
50,971 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8487 | HIGH | 7.5 | 0.3% | May 20, 2026 | Incorrect default permissions vulnerability in Progress Software MOVEit Automation allows Retrieve Embedded Sensitive Da... |
| CVE-2026-8486 | HIGH | 7.5 | 0.4% | May 20, 2026 | Allocation of resources without limits or throttling vulnerability in Progress Software MOVEit Automation allows Floodin... |
| CVE-2026-5783 | HIGH | 7.6 | 0.2% | May 20, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Beyaz Computer Sof... |
| CVE-2026-39047 | HIGH | 7.5 | 0.6% | May 20, 2026 | Buffer Overflow vulnerability in EPSON L14150 FL27PB allows a remote attacker to execute arbitrary code via the RAW Prin... |
| CVE-2026-8485 | HIGH | 7.5 | 0.3% | May 20, 2026 | Uncontrolled Memory Allocation vulnerability in Progress Software MOVEit Automation allows Excessive Allocation. This i... |
| CVE-2026-8469 | HIGH | 8.2 | 0.5% | May 20, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in phenixdigital phoenix_storybook allows unauthentic... |
| CVE-2026-22554 | HIGH | 7.8 | 0.2% | May 20, 2026 | MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerability |
| CVE-2026-5946 | HIGH | 7.5 | 1.9% | May 20, 2026 | Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`... |
| CVE-2026-45584 | HIGH | 8.1 | 0.9% | May 20, 2026 | Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network. |
| CVE-2026-45498 | HIGH | 7.5 | 63.1% | May 20, 2026 | Microsoft Defender Denial of Service Vulnerability |
| CVE-2026-42834 | HIGH | 7.8 | 0.4% | May 20, 2026 | Improper access control in Windows Admin Center allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-42383 | HIGH | 7.6 | 0.3% | May 20, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YITH YITH WooComme... |
| CVE-2026-41091 | HIGH | 7.8 | 8.4% | May 20, 2026 | Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to el... |
| CVE-2026-3039 | HIGH | 7.5 | 1.0% | May 20, 2026 | BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory ... |
| CVE-2026-29518 | HIGH | 7 | 0.2% | May 20, 2026 | Rsync versions before 3.4.3 contain a time-of-check to time-of-use (TOCTOU) race condition in daemon file handling that ... |
| CVE-2026-22315 | HIGH | 7.2 | 0.3% | May 20, 2026 | Incorrect Privilege Assignment vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component ... |
| CVE-2026-0856 | HIGH | 7.8 | 0.1% | May 20, 2026 | Improper Access Control vulnerability in Mesalvo Meona Client Launcher Component, Mesalvo Meona Server Component enables... |
| CVE-2026-9064 | HIGH | 7.5 | 0.8% | May 20, 2026 | A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function in the LDAP server does not enforce an uppe... |
| CVE-2026-44933 | HIGH | 8.5 | 0.2% | May 20, 2026 | `PluginScript` attempts to `chroot` the plugin to the `repoManagerRoot`, this root is frequently `/` (the system root) i... |
| CVE-2026-42959 | HIGH | 7.5 | 0.8% | May 20, 2026 | NLnet Labs Unbound up to and including version 1.25.0 has a denial of service vulnerability in the DNSSEC validator that... |
| CVE-2026-42944 | HIGH | 7.5 | 0.8% | May 20, 2026 | NLnet Labs Unbound 1.14.0 up to and including version 1.25.0 has a vulnerability that results in heap overflow when enco... |
| CVE-2026-41292 | HIGH | 7.5 | 0.7% | May 20, 2026 | NLnet Labs Unbound up to and including version 1.25.0 is vulnerable to a degradation of service attack related to parsin... |
| CVE-2026-41054 | HIGH | 7.8 | 0.2% | May 20, 2026 | In `src/havegecmd.c`, the `socket_handler` function performs a credential check on the abstract UNIX socket (`\0/sys/ent... |
| CVE-2026-40622 | HIGH | 7.5 | 0.2% | May 20, 2026 | NLnet Labs Unbound 1.16.2 up to and including version 1.25.0 has a vulnerability of the 'ghost domain names' family of a... |
| CVE-2026-5200 | HIGH | 8.8 | 0.3% | May 20, 2026 | The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is v... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now