2026 CVE Vulnerabilities
50,972 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8370 | HIGH | 8.5 | 0.1% | May 19, 2026 | Execution with unnecessary privileges vulnerability in Broadcom Automic Automation Agent Unix on Linux x64, Linux Power ... |
| CVE-2026-8073 | HIGH | 7.5 | 0.6% | May 19, 2026 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file del... |
| CVE-2026-41470 | HIGH | 8.2 | 0.5% | May 19, 2026 | LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows at... |
| CVE-2026-8604 | HIGH | 8.8 | 0.2% | May 19, 2026 | In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a vic... |
| CVE-2026-6009 | HIGH | 8.7 | 0.5% | May 19, 2026 | Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allow... |
| CVE-2026-47107 | HIGH | 8.6 | 0.2% | May 19, 2026 | Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files ... |
| CVE-2026-33633 | HIGH | 8.8 | 0.4% | May 19, 2026 | Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_dat... |
| CVE-2026-47358 | HIGH | 8.6 | 0.5% | May 19, 2026 | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded... |
| CVE-2026-47357 | HIGH | 8.6 | 0.5% | May 19, 2026 | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the rem... |
| CVE-2026-47356 | HIGH | 8.6 | 0.5% | May 19, 2026 | Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the fi... |
| CVE-2026-36828 | HIGH | 8.8 | 1.7% | May 19, 2026 | A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and includin... |
| CVE-2026-5804 | HIGH | 8.4 | 0.2% | May 19, 2026 | An improper authentication vulnerability was discovered in the Motorola Factory Test component (com.motorola.motocit). T... |
| CVE-2026-31069 | HIGH | 8.8 | 0.4% | May 19, 2026 | BillaBear (all versions prior to Jan 2026) contains a SQL Injection vulnerability in the EventRepository. User-controlle... |
| CVE-2026-47100 | HIGH | 8.7 | 0.5% | May 19, 2026 | Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public c... |
| CVE-2026-43634 | HIGH | 8.7 | 0.2% | May 19, 2026 | HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerability that allows unauthenticated remote attackers ... |
| CVE-2026-8975 | HIGH | 8.8 | 0.4% | May 19, 2026 | Memory safety bugs present in Firefox ESR 115.35, Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence... |
| CVE-2026-8974 | HIGH | 8.8 | 0.3% | May 19, 2026 | Memory safety bugs present in Firefox ESR 140.10 and Firefox 150. Some of these bugs showed evidence of memory corruptio... |
| CVE-2026-8973 | HIGH | 8.8 | 0.3% | May 19, 2026 | Memory safety bugs present in Firefox 150. Some of these bugs showed evidence of memory corruption and we presume that w... |
| CVE-2026-8972 | HIGH | 8.8 | 0.3% | May 19, 2026 | Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 1... |
| CVE-2026-8970 | HIGH | 8.8 | 0.3% | May 19, 2026 | Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunder... |
| CVE-2026-8969 | HIGH | 8.1 | 0.3% | May 19, 2026 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
| CVE-2026-8968 | HIGH | 7.5 | 0.4% | May 19, 2026 | Denial-of-service due to invalid pointer in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firef... |
| CVE-2026-8967 | HIGH | 7.5 | 0.3% | May 19, 2026 | Information disclosure in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 151 and Thunderbird 15... |
| CVE-2026-8966 | HIGH | 7.5 | 0.3% | May 19, 2026 | Information disclosure in the IP Protection component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
| CVE-2026-8965 | HIGH | 7.5 | 0.3% | May 19, 2026 | Information disclosure in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now