2026 CVE Vulnerabilities
50,998 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-21019 | HIGH | 8.6 | 0.2% | May 13, 2026 | Improper input validation in FacAtFunction in Galaxy Watch prior to SMR May-2026 Release 1 allows local attacker to exec... |
| CVE-2026-7635 | HIGH | 8.1 | 0.5% | May 13, 2026 | The coreActivity: Activity Logging for WordPress plugin for WordPress is vulnerable to PHP Object Injection in all versi... |
| CVE-2026-8201 | HIGH | 8.8 | 0.1% | May 13, 2026 | A use-after-free vulnerability exists in MongoDB's Field-Level Encryption (FLE) query analysis component, affecting clie... |
| CVE-2026-8199 | HIGH | 7.1 | 0.3% | May 13, 2026 | An authenticated user can cause excess memory usage via bitwise match expression AST processing of $bitsAllSet, $bitsAny... |
| CVE-2026-8053 | HIGH | 8.8 | 0.6% | May 13, 2026 | An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write priv... |
| CVE-2026-6888 | HIGH | 7.2 | 0.4% | May 13, 2026 | Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to execute arbitr... |
| CVE-2026-8108 | HIGH | 7.8 | 0.1% | May 12, 2026 | The installation of Fuji Tellus adds a driver to the kernel which grants all users read and write permissions. |
| CVE-2026-5371 | HIGH | 7.1 | 0.3% | May 12, 2026 | The MonsterInsights – Google Analytics Dashboard for WordPress (Website Stats Made Easy) plugin for WordPress is vulnera... |
| CVE-2026-44548 | HIGH | 8.1 | 0.1% | May 12, 2026 | ChurchCRM is an open-source church management system. Prior to 7.3.2, top-level cross-site GET navigation from an attack... |
| CVE-2026-43685 | HIGH | 7.2 | 0.5% | May 12, 2026 | A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to inject a... |
| CVE-2026-43680 | HIGH | 7.2 | 0.5% | May 12, 2026 | A Remote Code Execution vulnerability in Claris FileMaker Cloud allowed a user with Admin Console privileges to bypass a... |
| CVE-2026-42289 | HIGH | 8.8 | 0.1% | May 12, 2026 | ChurchCRM is an open-source church management system. Prior to 7.3.2, UserEditor.php processes user account creation and... |
| CVE-2026-42156 | HIGH | 7.1 | 0.3% | May 12, 2026 | Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and veri... |
| CVE-2026-1250 | HIGH | 7.5 | 0.3% | May 12, 2026 | The Court Reservation – Manage Your Court Bookings Online plugin for WordPress is vulnerable to generic SQL Injection vi... |
| CVE-2026-45227 | HIGH | 8.8 | 0.2% | May 12, 2026 | Heym before 0.0.21 contains a sandbox escape vulnerability in the custom Python tool executor that allows authenticated ... |
| CVE-2026-45226 | HIGH | 7.6 | 0.3% | May 12, 2026 | Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users ... |
| CVE-2026-45225 | HIGH | 7.6 | 0.4% | May 12, 2026 | Heym before 0.0.21 contains a path traversal vulnerability in the file upload endpoint that allows authenticated users t... |
| CVE-2026-44871 | HIGH | 8.8 | 1.2% | May 12, 2026 | Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS... |
| CVE-2026-44307 | HIGH | 8.7 | 0.6% | May 12, 2026 | Mako is a template library written in Python. Prior to 1.3.12, on Windows, a URI using backslash traversal (e.g. \..\..\... |
| CVE-2026-44304 | HIGH | 8.1 | 0.2% | May 12, 2026 | Lemur manages TLS certificate creation. Prior to 1.9.0, Lemur's LDAP authentication module (lemur/auth/ldap.py) construc... |
| CVE-2026-44302 | HIGH | 7.5 | 0.3% | May 12, 2026 | Snappier is a high performance C# implementation of the Snappy compression algorithm. Prior to 1.3.1, Snappier.SnappyStr... |
| CVE-2026-44301 | HIGH | 8.1 | 0.3% | May 12, 2026 | Hugo is a static site generator. From 0.43 to before 0.161.0, when building a Hugo site that uses Node-based asset pipel... |
| CVE-2026-44296 | HIGH | 7.5 | 0.3% | May 12, 2026 | Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.167, a remote, unauthenticated denial of service (DoS) vul... |
| CVE-2026-44260 | HIGH | 8.1 | 0.3% | May 12, 2026 | efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the readonly flag set on the <efw:elFinder> JSP tag is int... |
| CVE-2026-44241 | HIGH | 7.5 | 0.4% | May 12, 2026 | Micronaut Framework is a JVM-based full stack Java framework designed for building modular, easily testable JVM applicat... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now