2026 CVE Vulnerabilities
50,983 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44501 | HIGH | 7.1 | 0.1% | May 14, 2026 | DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserialize... |
| CVE-2026-42595 | HIGH | 8.6 | 0.3% | May 14, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, Gotenberg's Chromium URL-to-PDF endpoint (/f... |
| CVE-2026-42594 | HIGH | 7.5 | 0.3% | May 14, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the webhook middleware spawns a goroutine th... |
| CVE-2026-42591 | HIGH | 8.2 | 0.2% | May 14, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the LibreOffice conversion endpoint (/forms/... |
| CVE-2026-42590 | HIGH | 8.2 | 0.3% | May 14, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.30.0, The ExifTool metadata write blocklist in Got... |
| CVE-2026-42283 | HIGH | 7.8 | 0.2% | May 14, 2026 | DevSpace is a client-only developer tool for cloud-native development with Kubernetes. Prior to 6.3.21, DevSpace's UI se... |
| CVE-2026-42281 | HIGH | 8.6 | 1.6% | May 14, 2026 | MagicMirror² is an open source modular smart mirror platform. Prior to 2.36.0, an unauthenticated Server-Side Request Fo... |
| CVE-2026-40893 | HIGH | 8.2 | 0.3% | May 14, 2026 | Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, Gotenberg only checks if the tag is exactly ... |
| CVE-2026-44375 | HIGH | 7.5 | 0.4% | May 14, 2026 | Nerdbank.MessagePack is a NativeAOT-compatible MessagePack serialization library. Prior to 1.1.62, Nerdbank.MessagePack ... |
| CVE-2026-44216 | HIGH | 7.5 | 0.3% | May 14, 2026 | Wasmtime is a runtime for WebAssembly. From 30.0.0 to 36.0.8, 43.0.2, and 44.0.1, Wasmtime's allocation logic for a WebA... |
| CVE-2026-42881 | HIGH | 8.4 | 0.2% | May 14, 2026 | STIGQter is an open-source reimplementation of DISA's STIG Viewer. From 0.1.2 to before 1.2.7, an attacker can achieve l... |
| CVE-2026-42559 | HIGH | 8.8 | 0.2% | May 14, 2026 | RMCP is an official Rust SDK for the Model Context Protocol. Prior to version 1.4.0, the rmcp crate's Streamable HTTP se... |
| CVE-2026-42186 | HIGH | 7.5 | 0.2% | May 14, 2026 | OpenBao is an open source identity-based secrets management system. Prior to 2.5.3, when OpenBao's initial namespace del... |
| CVE-2026-41937 | HIGH | 8.6 | 0.4% | May 14, 2026 | Vvveb before 1.0.8.3 contains an unrestricted file upload vulnerability in the plugin upload endpoint that allows super_... |
| CVE-2026-41935 | HIGH | 7.1 | 0.3% | May 14, 2026 | Vvveb before 1.0.8.3 contains an uncontrolled recursion vulnerability in the admin controller dispatch cycle where Base:... |
| CVE-2026-24712 | HIGH | 7.3 | 0.9% | May 14, 2026 | Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection. |
| CVE-2026-6638 | HIGH | 8.8 | 0.2% | May 14, 2026 | SQL injection in PostgreSQL logical replication ALTER SUBSCRIPTION ... REFRESH PUBLICATION allows a subscriber table cre... |
| CVE-2026-6637 | HIGH | 8.8 | 0.4% | May 14, 2026 | Stack buffer overflow in PostgreSQL module "refint" allows an unprivileged database user to execute arbitrary code as th... |
| CVE-2026-6479 | HIGH | 7.5 | 0.5% | May 14, 2026 | Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allows an attacker able to connect to a PostgreSQL AF_UNIX ... |
| CVE-2026-6477 | HIGH | 8.8 | 0.5% | May 14, 2026 | Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lsee... |
| CVE-2026-6476 | HIGH | 7.2 | 0.3% | May 14, 2026 | SQL injection in PostgreSQL pg_createsubscriber allows an attacker with pg_create_subscription rights to execute arbitra... |
| CVE-2026-6475 | HIGH | 8.8 | 0.3% | May 14, 2026 | Symlink following in PostgreSQL pg_basebackup plain format and in pg_rewind allows an origin superuser to overwrite loca... |
| CVE-2026-6473 | HIGH | 8.8 | 1.0% | May 14, 2026 | Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to un... |
| CVE-2026-5798 | HIGH | 7.1 | 0.2% | May 14, 2026 | Unsafe object reference (IDOR) in Stel Order v3.25.1 and earlier versions, specifically in the ‘/app/FrontController’ en... |
| CVE-2026-4031 | HIGH | 7.5 | 0.5% | May 14, 2026 | The Database Backup for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now