2026 CVE Vulnerabilities
50,983 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-43907 | HIGH | 8.3 | 0.4% | May 14, 2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a... |
| CVE-2026-43906 | HIGH | 7.8 | 0.2% | May 14, 2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a... |
| CVE-2026-43905 | HIGH | 7.8 | 0.2% | May 14, 2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a... |
| CVE-2026-43904 | HIGH | 7.8 | 0.2% | May 14, 2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a... |
| CVE-2026-43903 | HIGH | 7.8 | 0.1% | May 14, 2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a... |
| CVE-2026-3290 | HIGH | 7.4 | 0.2% | May 14, 2026 | Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predictable values |
| CVE-2026-24899 | HIGH | 7.5 | 0.4% | May 14, 2026 | Fleet is open source device management software. Prior to version 4.82.0, a vulnerability in Fleet's Windows MDM enrollm... |
| CVE-2026-8621 | HIGH | 8.8 | 0.4% | May 14, 2026 | Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to i... |
| CVE-2026-45371 | HIGH | 7.2 | 0.2% | May 14, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan publish-mode Reader can mutate Con... |
| CVE-2026-44633 | HIGH | 8.1 | 0.3% | May 14, 2026 | Live Helper Chat is an open-source application that enables live support websites. In 4.84v, the Live Helper Chat REST A... |
| CVE-2026-44586 | HIGH | 8.3 | 0.3% | May 14, 2026 | SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace ... |
| CVE-2026-44522 | HIGH | 8.6 | 0.5% | May 14, 2026 | Note Mark is an open-source note-taking application. From 0.13.0 to before 0.19.4, the Note Mark application allows auth... |
| CVE-2026-27886 | HIGH | 7.5 | 0.6% | May 14, 2026 | Strapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did n... |
| CVE-2026-23998 | HIGH | 7.5 | 0.2% | May 14, 2026 | Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet’s Windows MDM managem... |
| CVE-2026-22599 | HIGH | 7.2 | 1.2% | May 14, 2026 | Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.... |
| CVE-2026-6332 | HIGH | 7.5 | 0.1% | May 14, 2026 | CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive ... |
| CVE-2026-42334 | HIGH | 7.5 | 0.3% | May 14, 2026 | Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.9, 7.8.9, 8.22... |
| CVE-2026-41615 | HIGH | 7.4 | 0.6% | May 14, 2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to... |
| CVE-2026-44827 | HIGH | 8.8 | 0.6% | May 14, 2026 | Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, diffusers 0.37.0 allows remote code execut... |
| CVE-2026-44516 | HIGH | 7.6 | 0.2% | May 14, 2026 | Valtimo is an open-source business process automation platform. From 12.4.0 to 12.33.0 and 13.26.0, the LoggingRestClien... |
| CVE-2026-44513 | HIGH | 8.8 | 1.1% | May 14, 2026 | Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPip... |
| CVE-2026-44511 | HIGH | 7.4 | 0.2% | May 14, 2026 | Katalyst Koi is a framework for building Rails admin functionality. Prior to 4.20.0 and 5.6.0, admin session cookies wer... |
| CVE-2026-20224 | HIGH | 8.6 | 0.7% | May 14, 2026 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated,... |
| CVE-2026-44504 | HIGH | 8.6 | 0.3% | May 14, 2026 | Aegra is a drop-in replacement for LangSmith Deployments. Prior to 0.9.7, with multiple authenticated users on a shared ... |
| CVE-2026-44503 | HIGH | 7 | 0.5% | May 14, 2026 | The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and othe... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now