2026 CVE Vulnerabilities
50,977 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46362 | HIGH | 7.1 | 0.3% | May 15, 2026 | phpMyFAQ before 4.1.2 contains an authorization bypass vulnerability in AbstractAdministrationController::userHasPermiss... |
| CVE-2026-46361 | HIGH | 8.2 | 0.2% | May 15, 2026 | phpMyFAQ before 4.1.2 contains a stored cross-site scripting vulnerability in search.twig where result.question and resu... |
| CVE-2026-46359 | HIGH | 7.7 | 0.2% | May 15, 2026 | phpMyFAQ before 4.1.2 contains a sql injection vulnerability in CurrentUser::setTokenData that allows authenticated atta... |
| CVE-2026-45800 | HIGH | 8.7 | 0.3% | May 15, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3... |
| CVE-2026-45008 | HIGH | 7 | 0.3% | May 15, 2026 | phpMyFAQ before 4.1.2 contains a path traversal vulnerability in Client::deleteClientFolder that allows admins with INST... |
| CVE-2026-44826 | HIGH | 7.5 | 0.2% | May 15, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.2... |
| CVE-2026-46474 | HIGH | 7.5 | 0.3% | May 15, 2026 | Trog::TOTP versions before 1.006 for Perl generate secrets using rand. Secrets were generated using Perl's built-in ran... |
| CVE-2026-45539 | HIGH | 7.4 | 0.7% | May 15, 2026 | Microsoft APM is an open-source, community-driven dependency manager for AI agents. From 0.5.4 to 0.12.4, two primitive ... |
| CVE-2026-45038 | HIGH | 7.8 | 0.2% | May 15, 2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, since Tabby does not escape cont... |
| CVE-2026-45037 | HIGH | 7.1 | 0.1% | May 15, 2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.232, Tabby's terminal linkifier passe... |
| CVE-2026-45036 | HIGH | 7 | 0.1% | May 15, 2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby before 1.0.233 automatical... |
| CVE-2026-45035 | HIGH | 8.8 | 0.4% | May 15, 2026 | Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby registers itself as the ha... |
| CVE-2026-44714 | HIGH | 7.5 | 0.3% | May 15, 2026 | The bitcoinj library is a Java implementation of the Bitcoin protocol. Prior to 0.17.1, ScriptExecution.correctlySpends(... |
| CVE-2026-44641 | HIGH | 7.1 | 0.4% | May 15, 2026 | Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.8.12, Microsoft APM norma... |
| CVE-2026-46508 | HIGH | 7.8 | 0.2% | May 15, 2026 | Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14000, the Turborepo ... |
| CVE-2026-35194 | HIGH | 8.1 | 0.4% | May 15, 2026 | Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated u... |
| CVE-2026-46483 | HIGH | 7 | 0.6% | May 15, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimu... |
| CVE-2026-45736 | HIGH | 7.5 | 0.7% | May 15, 2026 | ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is v... |
| CVE-2026-39054 | HIGH | 7.3 | 1.4% | May 15, 2026 | Oinone Pamirs 7.0.0 contains a command injection vulnerability in CommandHelper.executeCommands. The method starts a she... |
| CVE-2026-38728 | HIGH | 7.5 | 0.6% | May 15, 2026 | An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStr... |
| CVE-2026-34253 | HIGH | 8.2 | 0.5% | May 15, 2026 | A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in functi... |
| CVE-2026-46333 | HIGH | 7.1 | 1.5% | May 15, 2026 | In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The ... |
| CVE-2026-41552 | HIGH | 7.5 | 0.5% | May 15, 2026 | PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sani... |
| CVE-2026-41964 | HIGH | 8.4 | 0.1% | May 15, 2026 | Permission control vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availabili... |
| CVE-2026-6403 | HIGH | 7.5 | 0.8% | May 15, 2026 | The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now