2026 CVE Vulnerabilities
50,987 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42463 | HIGH | 8.1 | 0.2% | May 13, 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cr... |
| CVE-2026-32993 | HIGH | 8.3 | 0.3% | May 13, 2026 | Improper sanitization of the `status` query parameter of the `/unprotected/nova_error` endpoint allows unauthenticated a... |
| CVE-2026-32992 | HIGH | 8.2 | 0.3% | May 13, 2026 | SSL verification is disabled in the DNS Cluster system. This could allow for a malicious server to man-in-the-middle the... |
| CVE-2026-29205 | HIGH | 8.6 | 7.2% | May 13, 2026 | Incorrect privileges management and insufficient path filtering allow to read arbitrary file on the server via the cpdav... |
| CVE-2026-45708 | HIGH | 7.2 | 0.3% | May 13, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.3, an admin with documents edit permission can save raw <?php …... |
| CVE-2026-45229 | HIGH | 8.8 | 0.4% | May 13, 2026 | Quark Drive before 0.8.5 contains a mass assignment vulnerability in the POST /update endpoint that allows authenticated... |
| CVE-2026-45055 | HIGH | 8.1 | 0.1% | May 13, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.2, CubeCart 6.6.x – 6.7.1 builds CC_STORE_URL directly from the... |
| CVE-2026-44418 | HIGH | 8.7 | 0.3% | May 13, 2026 | EcclesiaCRM is CRM Software for church management. In 8.0.0 and earlier, the ValidateInput() function's default case in ... |
| CVE-2026-44380 | HIGH | 7.2 | 0.4% | May 13, 2026 | MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerabili... |
| CVE-2026-42602 | HIGH | 8.1 | 0.2% | May 13, 2026 | azureauthextension is the Azure Authenticator Extension. From 0.124.0 to 0.150.0, a server-side authentication bypass in... |
| CVE-2026-42561 | HIGH | 7.5 | 0.7% | May 13, 2026 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service v... |
| CVE-2026-42304 | HIGH | 7.5 | 0.4% | May 13, 2026 | Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.n... |
| CVE-2026-39358 | HIGH | 7.2 | 0.3% | May 13, 2026 | CubeCart is an ecommerce software solution. Prior to 6.6.0, Authenticated Time-Based Blind SQL Injection vulnerabilities... |
| CVE-2026-21821 | HIGH | 8.3 | 0.2% | May 13, 2026 | The HCL BigFix SCM Reporting site contains an outdated and unsupported version of the jQuery 1.x library. Since jQuery 1... |
| CVE-2026-42552 | HIGH | 7.5 | 0.3% | May 13, 2026 | Flight is an extensible micro-framework for PHP. Prior to 3.18.1, the default error handler Engine::_error() writes the ... |
| CVE-2026-42551 | HIGH | 7.5 | 0.3% | May 13, 2026 | Flight is an extensible micro-framework for PHP. Prior to 3.18.1, Request::getMethod() unconditionally honors the X-HTTP... |
| CVE-2026-42550 | HIGH | 8.8 | 0.4% | May 13, 2026 | Flight is an extensible micro-framework for PHP. Prior to 3.18.1, SimplePdo::insert(), SimplePdo::update(), and SimplePd... |
| CVE-2026-42548 | HIGH | 8.6 | 0.3% | May 13, 2026 | Flight is an extensible micro-framework for PHP. Prior to 3.18.1, Flight::jsonp() concatenates the ?jsonp= query paramet... |
| CVE-2026-33381 | HIGH | 8.1 | 0.2% | May 13, 2026 | When a user's access to mint tokens for a service account is revoked, it is sometimes still possible to do so for a few ... |
| CVE-2026-33377 | HIGH | 7.1 | 0.2% | May 13, 2026 | An Editor can overwrite a dashboard not owned by them to acquire admin on that specific dashboard. The user must have wr... |
| CVE-2026-33376 | HIGH | 7.4 | 0.3% | May 13, 2026 | When using an IPv6 allow-list for the Auth Proxy feature, it defaults to /32 addresses. Addresses specifying a mask expl... |
| CVE-2026-8466 | HIGH | 8.2 | 0.4% | May 13, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in ninenines cowboy allows denial of service via unbo... |
| CVE-2026-44248 | HIGH | 7.5 | 0.5% | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the MQTT ... |
| CVE-2026-43970 | HIGH | 8.2 | 0.5% | May 13, 2026 | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in ninenines cowlib allows unauthenticate... |
| CVE-2026-42587 | HIGH | 7.5 | 1.0% | May 13, 2026 | Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, HttpConte... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now