2026 CVE Vulnerabilities
51,054 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-43983 | HIGH | 8.1 | 0.2% | May 12, 2026 | Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, Th... |
| CVE-2026-43939 | HIGH | 7.3 | 0.2% | May 12, 2026 | YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature acc... |
| CVE-2026-43938 | HIGH | 8.1 | 0.3% | May 12, 2026 | YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNE... |
| CVE-2026-43937 | HIGH | 8.8 | 0.5% | May 12, 2026 | YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects... |
| CVE-2026-42260 | HIGH | 8.2 | 0.2% | May 12, 2026 | Open-WebSearch is a multi-engine MCP server, CLI, and local daemon for agent web search and content retrieval. Prior to ... |
| CVE-2026-32687 | HIGH | 7.8 | 0.2% | May 12, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgr... |
| CVE-2026-8390 | HIGH | 7.3 | 0.3% | May 12, 2026 | Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3. |
| CVE-2026-8389 | HIGH | 8.8 | 0.3% | May 12, 2026 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3. |
| CVE-2026-6865 | HIGH | 7.1 | 0.3% | May 12, 2026 | CWE-22: Improper Limitation of a Pathname to a Restricted Directory (“Path Traversal”) vulnerability that could cause un... |
| CVE-2026-43916 | HIGH | 8.7 | 0.3% | May 12, 2026 | pam_authnft is a PAM session module binding nftables firewall rules to authenticated sessions via cgroupv2 inodes. Prior... |
| CVE-2026-35071 | HIGH | 8.2 | 0.5% | May 12, 2026 | Dell PowerScale InsightIQ, versions 6.0.0 through 6.2.0, contains an improper neutralization of special elements used in... |
| CVE-2026-4827 | HIGH | 8.7 | 0.3% | May 12, 2026 | CWE‑331: Insufficient Entropy vulnerability exists that could lead to unauthorized access when an attacker on the networ... |
| CVE-2026-45218 | HIGH | 7.7 | 0.2% | May 12, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Trave... |
| CVE-2026-45214 | HIGH | 8.5 | 0.2% | May 12, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpro Xpro Elemento... |
| CVE-2026-45213 | HIGH | 7.6 | 0.2% | May 12, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 BEAR wo... |
| CVE-2026-45211 | HIGH | 8.5 | 0.2% | May 12, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExpe... |
| CVE-2026-42742 | HIGH | 8.5 | 0.2% | May 12, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Views for WPF... |
| CVE-2026-42741 | HIGH | 8.5 | 0.2% | May 12, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman Ninja Forms V... |
| CVE-2026-41713 | HIGH | 8.2 | 0.2% | May 12, 2026 | A malicious user could craft input that is stored in conversation memory and later interpreted by the model in an uninte... |
| CVE-2026-41712 | HIGH | 7.5 | 0.3% | May 12, 2026 | Spring AI's chat memory component contained a problematic default that, when not explicitly overridden, could result in ... |
| CVE-2026-2465 | HIGH | 8.8 | 0.2% | May 12, 2026 | Incorrect Authorization vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry an... |
| CVE-2026-8162 | HIGH | 7.5 | 0.3% | May 12, 2026 | multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/f... |
| CVE-2026-8161 | HIGH | 7.5 | 0.5% | May 12, 2026 | multiparty@4.2.3 and lower versions are vulnerable to denial of service via uncaught exception. By sending a multipart/f... |
| CVE-2026-8159 | HIGH | 7.5 | 0.3% | May 12, 2026 | multiparty@4.2.3 and lower versions are vulnerable to denial of service via regular expression backtracking in the Conte... |
| CVE-2026-6001 | HIGH | 8.8 | 0.2% | May 12, 2026 | Authorization bypass through User-Controlled key vulnerability in ABIS Technology Ltd. Co. BAPSİS allows Exploitation of... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now