2026 CVE Vulnerabilities
50,981 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34253 | HIGH | 8.2 | 0.5% | May 15, 2026 | A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in functi... |
| CVE-2026-46333 | HIGH | 7.1 | 1.5% | May 15, 2026 | In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The ... |
| CVE-2026-41552 | HIGH | 7.5 | 0.5% | May 15, 2026 | PDF Export Module used in DHTMLX's products Gantt and Scheduler is vulnerable to Path Traversal due to lack of HTML sani... |
| CVE-2026-41964 | HIGH | 8.4 | 0.1% | May 15, 2026 | Permission control vulnerability in the web. Impact: Successful exploitation of this vulnerability may affect availabili... |
| CVE-2026-6403 | HIGH | 7.5 | 0.8% | May 15, 2026 | The Quick Playground plugin for WordPress is vulnerable to Path Traversal in versions up to and including 1.3.3. This is... |
| CVE-2026-6228 | HIGH | 8.8 | 0.3% | May 15, 2026 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in versions up to and includ... |
| CVE-2026-44088 | HIGH | 8.6 | 0.4% | May 15, 2026 | SzafirHost verifies the signature of the downloaded JAR file using class JarInputStream (reading from the beginning of t... |
| CVE-2026-8654 | HIGH | 8.7 | 0.2% | May 15, 2026 | Improper input validation in Delphix Continuous Data connectors allows an authenticated user to execute arbitrary operat... |
| CVE-2026-4094 | HIGH | 8.1 | 0.3% | May 15, 2026 | The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss du... |
| CVE-2026-41702 | HIGH | 7 | 0.1% | May 15, 2026 | VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a... |
| CVE-2026-43490 | HIGH | 8.8 | 0.4% | May 15, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate inherited ACE SID length smb_inher... |
| CVE-2026-28761 | HIGH | 8.5 | 0.1% | May 15, 2026 | Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 a... |
| CVE-2026-7373 | HIGH | 8.5 | 0.2% | May 15, 2026 | Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows a user to gain SYSTEM level contr... |
| CVE-2026-2652 | HIGH | 8.6 | 1.5% | May 15, 2026 | A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when... |
| CVE-2026-0432 | HIGH | 8.5 | 0.1% | May 15, 2026 | Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achiev... |
| CVE-2026-44671 | HIGH | 7.5 | 0.5% | May 14, 2026 | ZITADEL is an open source identity management platform. From 2.71.11 to before 3.4.10 and 4.15.0, a vulnerability was di... |
| CVE-2026-45370 | HIGH | 7.7 | 0.2% | May 14, 2026 | python-utcp is the python implementation of UTCP. Prior to 1.1.3, _prepare_environment() in cli_communication_protocol.p... |
| CVE-2026-45369 | HIGH | 8.3 | 0.3% | May 14, 2026 | python-utcp is the python implementation of UTCP. Prior to 1.1.3, the _substitute_utcp_args method in cli_communication_... |
| CVE-2026-44700 | HIGH | 8.7 | 0.3% | May 14, 2026 | Elixir WebRTC is an Elixir implementation of the W3C WebRTC API. Prior to 0.15.1 and 0.16.1, missing DTLS peer certifica... |
| CVE-2026-44678 | HIGH | 7.1 | 0.2% | May 14, 2026 | Tuist is a virtual platform team for Swift app devs. In 1.180.8 and earlier, the DELETE /api/projects/{account_handle}/{... |
| CVE-2026-44673 | HIGH | 7.5 | 0.4% | May 14, 2026 | libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an ... |
| CVE-2026-44647 | HIGH | 7.1 | 0.3% | May 14, 2026 | OneDev is a Git server with CI/CD, kanban, and packages. Prior to 15.0.2, there is behavior that breaks the expected bou... |
| CVE-2026-42847 | HIGH | 7.1 | 0.2% | May 14, 2026 | ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #122, there is a critical SQL Injection (SQLi) ... |
| CVE-2026-42327 | HIGH | 8.7 | 0.2% | May 14, 2026 | rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.7 to before 0.10.79, X509Ref::ocsp_re... |
| CVE-2026-8629 | HIGH | 8.6 | 0.3% | May 14, 2026 | Crabbox prior to v0.12.0 contains a privilege escalation vulnerability that allows users with shared visibility-only acc... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now