2026 CVE Vulnerabilities
50,974 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-26978 | HIGH | 8.6 | 0.9% | May 18, 2026 | FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize dat... |
| CVE-2026-22810 | HIGH | 7.3 | 0.2% | May 18, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior... |
| CVE-2026-47092 | HIGH | 7.8 | 0.5% | May 18, 2026 | Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attac... |
| CVE-2026-45245 | HIGH | 7.4 | 0.3% | May 18, 2026 | Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch ... |
| CVE-2026-45242 | HIGH | 7.1 | 0.4% | May 18, 2026 | Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/summarize daemon endpoint that allows authe... |
| CVE-2026-29963 | HIGH | 7.5 | 0.6% | May 18, 2026 | HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper validation of user-supplied input in the /t... |
| CVE-2026-29962 | HIGH | 7.5 | 0.4% | May 18, 2026 | HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user-suppli... |
| CVE-2026-8843 | HIGH | 7.1 | 0.2% | May 18, 2026 | Creating a "2dsphere_bucket" index on a non-timeseries bucket collection will succeed, but any subsequent attempt to ins... |
| CVE-2026-41085 | HIGH | 8.8 | 0.3% | May 18, 2026 | Thermo Fisher Scientific Torrent Suite Dx through 5.14.2 has a privilege escalation vulnerability that may allow an auth... |
| CVE-2026-41949 | HIGH | 7.5 | 0.4% | May 18, 2026 | Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any a... |
| CVE-2026-39079 | HIGH | 7.5 | 0.3% | May 18, 2026 | An issue in prestashop upsshipping all versions through at least 2.4.0 allows a remote attacker to obtain sensitive info... |
| CVE-2026-26462 | HIGH | 7.3 | 0.3% | May 18, 2026 | Offline Hospital Management System 5.3.0 allows remote code execution due to an improper Electron renderer configuration... |
| CVE-2026-42009 | HIGH | 7.5 | 1.3% | May 18, 2026 | A flaw was found in gnutls. A remote attacker could exploit an issue in the Datagram Transport Layer Security (DTLS) pac... |
| CVE-2026-0983 | HIGH | 7.1 | 0.2% | May 18, 2026 | Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 all... |
| CVE-2026-7498 | HIGH | 8.8 | 0.3% | May 18, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Informatio... |
| CVE-2026-6902 | HIGH | 7.7 | 0.4% | May 18, 2026 | A Remote Code Execution vulnerability in P4 (Helix Core) Server's Command-Line Client, prior to the 2025.2 Patch 2, has ... |
| CVE-2026-6347 | HIGH | 7.6 | 0.3% | May 18, 2026 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fie... |
| CVE-2026-6346 | HIGH | 8.7 | 0.3% | May 18, 2026 | Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fie... |
| CVE-2026-8788 | HIGH | 7.3 | 0.2% | May 18, 2026 | Net::Statsd::Lite versions through 0.10.0 for Perl allowed metric injections. The values from the set_add method were n... |
| CVE-2026-6495 | HIGH | 7.1 | 0.2% | May 18, 2026 | The Ajax Load More WordPress plugin before 7.8.4 does not sanitise and escape a parameter before outputting it back in ... |
| CVE-2026-6381 | HIGH | 7.5 | 0.4% | May 18, 2026 | The WP Maps WordPress plugin before 4.9.3 does not properly sanitize a parameter before using it in a file path, allowi... |
| CVE-2026-6379 | HIGH | 8.6 | 0.3% | May 18, 2026 | The WP Photo Album Plus WordPress plugin before 9.1.11.001 does not properly sanitize and escape a parameter before usin... |
| CVE-2026-3220 | HIGH | 8.8 | 0.3% | May 18, 2026 | The Autoptimize WordPress plugin before 3.1.15, Clearfy Cache WordPress plugin before 2.4.2, Speed Optimizer WordPress... |
| CVE-2026-8785 | HIGH | 7.3 | 0.3% | May 18, 2026 | A flaw has been found in projectworlds hospital-management-system-in-php 1.0. Affected by this vulnerability is the func... |
| CVE-2026-8776 | HIGH | 8.8 | 0.4% | May 18, 2026 | A vulnerability has been found in Edimax BR-6428NS 1.10. This vulnerability affects the function formPPTPSetup of the fi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now