2026 CVE Vulnerabilities
50,972 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8964 | HIGH | 7.5 | 0.3% | May 19, 2026 | Spoofing issue in the Popup Blocker component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
| CVE-2026-8963 | HIGH | 7.5 | 0.3% | May 19, 2026 | Spoofing issue in the Web Speech component. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
| CVE-2026-8962 | HIGH | 8.1 | 0.4% | May 19, 2026 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thund... |
| CVE-2026-8960 | HIGH | 7.5 | 0.4% | May 19, 2026 | Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and Thunderbird 151. |
| CVE-2026-8958 | HIGH | 8.6 | 0.3% | May 19, 2026 | Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Fi... |
| CVE-2026-8957 | HIGH | 8.8 | 0.4% | May 19, 2026 | Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.... |
| CVE-2026-8955 | HIGH | 8.8 | 0.4% | May 19, 2026 | Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thu... |
| CVE-2026-8954 | HIGH | 7.5 | 0.4% | May 19, 2026 | Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 15... |
| CVE-2026-8952 | HIGH | 8.8 | 0.4% | May 19, 2026 | Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 151 and Thunderbird 15... |
| CVE-2026-8949 | HIGH | 7.5 | 0.6% | May 19, 2026 | Integer overflow in the Widget: Win32 component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunde... |
| CVE-2026-8947 | HIGH | 7.3 | 0.4% | May 19, 2026 | Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36,... |
| CVE-2026-8946 | HIGH | 7.5 | 0.6% | May 19, 2026 | Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Fir... |
| CVE-2026-8945 | HIGH | 7.5 | 0.4% | May 19, 2026 | Sandbox escape in Firefox and Firefox Focus for Android. This vulnerability was fixed in Firefox 151. |
| CVE-2026-42100 | HIGH | 7.5 | 0.7% | May 19, 2026 | Improper Handling of Syntactically Invalid Structure in Sparx Pro Cloud Server allows Denial of Service (DoS) attack to ... |
| CVE-2026-42099 | HIGH | 7.5 | 0.7% | May 19, 2026 | Sparx Pro Cloud Server is vulnerable to a Race Condition in the /data_api/dl_internal_artifact.php endpoint. The applica... |
| CVE-2026-42098 | HIGH | 8.7 | 0.4% | May 19, 2026 | Sparx Enterprise Architect software has a security feature that limits user's actions to those specified in the role. An... |
| CVE-2026-42097 | HIGH | 8.8 | 0.9% | May 19, 2026 | Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "model" query parameter ... |
| CVE-2026-42096 | HIGH | 8.8 | 0.6% | May 19, 2026 | Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to lack of per... |
| CVE-2026-23558 | HIGH | 7.8 | 0.1% | May 19, 2026 | The adjustments made for XSA-379 as well as those subsequently becoming XSA-387 still left a race window, when a HVM or ... |
| CVE-2026-8912 | HIGH | 7.5 | 0.4% | May 19, 2026 | The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to... |
| CVE-2026-7571 | HIGH | 7.1 | 0.3% | May 19, 2026 | A flaw was found in Keycloak. A low-privilege user, with knowledge of user credentials and client ID, can bypass a secur... |
| CVE-2026-7507 | HIGH | 7.5 | 0.6% | May 19, 2026 | A session fixation vulnerability was found in Keycloak's login-actions endpoints. An unauthenticated attacker could expl... |
| CVE-2026-7504 | HIGH | 8.1 | 0.5% | May 19, 2026 | A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an atta... |
| CVE-2026-7307 | HIGH | 7.5 | 0.7% | May 19, 2026 | A flaw was found in Keycloak. A remote, unauthenticated attacker can send a specially crafted XML input to the Security ... |
| CVE-2026-8827 | HIGH | 8.2 | 0.3% | May 19, 2026 | The AddressRepository::getSqlQuery() method constructs a database query without properly sanitizing user input, leading ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now