2026 CVE Vulnerabilities
51,011 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34647 | HIGH | 7.4 | 0.6% | May 12, 2026 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a S... |
| CVE-2026-34646 | HIGH | 7.5 | 0.4% | May 12, 2026 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an ... |
| CVE-2026-34645 | HIGH | 7.5 | 0.6% | May 12, 2026 | Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an ... |
| CVE-2026-23827 | HIGH | 7.5 | 0.5% | May 12, 2026 | A heap-based buffer overflow vulnerability exists in a Network management service of AOS-8 and AOS-10 that could allow a... |
| CVE-2026-23826 | HIGH | 7.5 | 0.4% | May 12, 2026 | A vulnerability in a network management service of AOS-8 Operating System could allow an unauthenticated remote attacker... |
| CVE-2026-23825 | HIGH | 7.5 | 0.3% | May 12, 2026 | Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacke... |
| CVE-2026-23824 | HIGH | 7.5 | 0.3% | May 12, 2026 | Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacke... |
| CVE-2026-8429 | HIGH | 8.8 | 0.5% | May 12, 2026 | SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the private space that allows attackers t... |
| CVE-2026-34684 | HIGH | 7.8 | 0.1% | May 12, 2026 | Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could resul... |
| CVE-2026-34683 | HIGH | 7.8 | 0.1% | May 12, 2026 | Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could resul... |
| CVE-2026-34682 | HIGH | 7.8 | 0.1% | May 12, 2026 | Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could resul... |
| CVE-2026-34681 | HIGH | 7.8 | 0.1% | May 12, 2026 | Substance3D - Designer versions 15.1.0 and earlier are affected by an out-of-bounds write vulnerability that could resul... |
| CVE-2026-23823 | HIGH | 7.2 | 1.0% | May 12, 2026 | A vulnerability in the command line interface of Access Points running AOS-10 could allow an authenticated remote attack... |
| CVE-2026-23821 | HIGH | 7.2 | 0.6% | May 12, 2026 | A vulnerability in the configuration processing logic of Access Points running AOS-10 could allow an authenticated remot... |
| CVE-2026-23820 | HIGH | 7.2 | 0.6% | May 12, 2026 | A vulnerability in the command line interface of Access Points running AOS-10 and AOS-8 Instant could allow an authentic... |
| CVE-2026-23819 | HIGH | 8.8 | 0.3% | May 12, 2026 | A vulnerability in the web-based management interface of Access Points running AOS-10 and AOS-8 Instant could allow an u... |
| CVE-2026-44184 | HIGH | 8 | 0.1% | May 12, 2026 | Cleanuparr is a tool for automating the cleanup of unwanted or blocked files in Sonarr, Radarr, and supported download c... |
| CVE-2026-44167 | HIGH | 7.5 | 0.2% | May 12, 2026 | phpseclib is a PHP secure communications library. Prior to 1.0.29, 2.0.54, and 3.0.52, anyone loading untrusted ASN1 fil... |
| CVE-2026-44166 | HIGH | 7.6 | 0.2% | May 12, 2026 | Pocketbase is an open source web backend written in go. Prior to 0.22.42 and 0.37.4, in some situations, if an attacker ... |
| CVE-2026-43929 | HIGH | 8.2 | 0.2% | May 12, 2026 | ssrfcheck is a library that checks if a string contains a potential SSRF attack. In 1.3.0 and earlier, ssrfcheck fails t... |
| CVE-2026-43892 | HIGH | 8.8 | 0.3% | May 12, 2026 | AntSword is a cross-platform website management toolkit. Prior to 2.1.16, incomplete noxss() sanitization leads to 1-cli... |
| CVE-2026-43891 | HIGH | 7.5 | 0.4% | May 12, 2026 | changedetection.io is a free open source web page change detection tool. Prior to 0.55.1, the vulnerability is caused by... |
| CVE-2026-42899 | HIGH | 7.5 | 2.4% | May 12, 2026 | Loop with unreachable exit condition ('infinite loop') in ASP.NET Core allows an unauthorized attacker to deny service o... |
| CVE-2026-42896 | HIGH | 7.8 | 0.3% | May 12, 2026 | Integer overflow or wraparound in Windows DWM Core Library allows an authorized attacker to elevate privileges locally. |
| CVE-2026-42893 | HIGH | 7.5 | 0.4% | May 12, 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now