2026 CVE Vulnerabilities
51,072 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28848 | HIGH | 7.5 | 0.5% | May 11, 2026 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Tahoe ... |
| CVE-2026-28847 | HIGH | 8.8 | 0.6% | May 11, 2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5, iOS 18.7.9 and iPadOS 18.7.9,... |
| CVE-2026-28846 | HIGH | 7.5 | 0.7% | May 11, 2026 | A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS ... |
| CVE-2026-28840 | HIGH | 7.8 | 0.1% | May 11, 2026 | A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonom... |
| CVE-2026-8321 | HIGH | 7.3 | 0.4% | May 11, 2026 | A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function createDevContext of the f... |
| CVE-2026-36734 | HIGH | 8.8 | 1.0% | May 11, 2026 | EDIMAX BR-6428nS V3 1.15 is vulnerable to Command Injection. An authenticated attacker with access to the network can su... |
| CVE-2026-2614 | HIGH | 7.5 | 2.9% | May 11, 2026 | A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 ... |
| CVE-2026-7790 | HIGH | 7.5 | 0.4% | May 11, 2026 | Uncontrolled Resource Consumption vulnerability in ninenines cowlib (cow_http_te module) allows Excessive Allocation. T... |
| CVE-2026-45224 | HIGH | 7.1 | 0.1% | May 11, 2026 | Crabbox before 0.9.0 contains a path traversal vulnerability in the Islo provider's workspace path resolution that allow... |
| CVE-2026-45223 | HIGH | 8.8 | 0.4% | May 11, 2026 | Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user-token verification path whe... |
| CVE-2026-7210 | HIGH | 7.5 | 0.8% | May 11, 2026 | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow... |
| CVE-2026-5172 | HIGH | 7.3 | 2.7% | May 11, 2026 | A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and ... |
| CVE-2026-4892 | HIGH | 8.4 | 0.8% | May 11, 2026 | A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute... |
| CVE-2026-4890 | HIGH | 7.5 | 8.8% | May 11, 2026 | A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of... |
| CVE-2026-45006 | HIGH | 8.8 | 0.5% | May 11, 2026 | OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and confi... |
| CVE-2026-45004 | HIGH | 8.4 | 0.1% | May 11, 2026 | OpenClaw before 2026.4.23 contains an arbitrary code execution vulnerability in the bundled plugin setup resolver that l... |
| CVE-2026-45001 | HIGH | 7.1 | 0.2% | May 11, 2026 | OpenClaw before 2026.4.20 contains a guard bypass vulnerability in the agent-facing gateway config.patch and config.appl... |
| CVE-2026-44995 | HIGH | 7.3 | 0.1% | May 11, 2026 | OpenClaw before 2026.4.20 contains an improper environment variable validation vulnerability in MCP stdio server configu... |
| CVE-2026-44413 | HIGH | 7.5 | 0.3% | May 11, 2026 | In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access |
| CVE-2026-43640 | HIGH | 8.6 | 0.5% | May 11, 2026 | Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an or... |
| CVE-2026-42860 | HIGH | 8.5 | 0.3% | May 11, 2026 | The Open edx Enterprise Service app provides enterprise features to the Open edX platform. From 7.0.2 to 7.0.4, the sync... |
| CVE-2026-42859 | HIGH | 8.1 | 0.5% | May 11, 2026 | Neat VNC is a VNC server library. Prior to 0.9.6, a pre-authentication stack buffer overflow exists in neatvnc in the RS... |
| CVE-2026-42856 | HIGH | 8.7 | 0.5% | May 11, 2026 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to 5.1.3, the MCP HTTP transport accepts JSON-RPC too... |
| CVE-2026-42313 | HIGH | 8.3 | 0.4% | May 11, 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API... |
| CVE-2026-41431 | HIGH | 8 | 0.2% | May 11, 2026 | Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser ships a Mozilla Application Resource (MAR) updater (org.mo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now