2026 CVE Vulnerabilities
51,076 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7818 | HIGH | 7.8 | 0.1% | May 11, 2026 | Deserialization of untrusted data (CWE-502) in pgAdmin 4 FileBackedSessionManager. The session manager performed unsafe... |
| CVE-2026-7817 | HIGH | 7.1 | 0.2% | May 11, 2026 | Local file inclusion (LFI) and server-side request forgery (SSRF) vulnerabilities in pgAdmin 4 LLM API configuration end... |
| CVE-2026-7816 | HIGH | 8.8 | 1.4% | May 11, 2026 | OS command injection (CWE-78) vulnerability in pgAdmin 4 Import/Export query export. User-supplied input was interpolat... |
| CVE-2026-7815 | HIGH | 8.8 | 0.5% | May 11, 2026 | SQL injection vulnerability in pgAdmin 4 Maintenance Tool. Four user-supplied JSON fields (buffer_usage_limit, vacuum_p... |
| CVE-2026-42611 | HIGH | 8.9 | 0.3% | May 11, 2026 | Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged (with the ability to create a page) user can ... |
| CVE-2026-42609 | HIGH | 8.1 | 0.5% | May 11, 2026 | Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows ... |
| CVE-2026-34092 | HIGH | 7.5 | 0.2% | May 11, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulne... |
| CVE-2026-34091 | HIGH | 7.5 | 0.3% | May 11, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue ... |
| CVE-2026-34090 | HIGH | 7.5 | 0.3% | May 11, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation CheckUser. This issue ... |
| CVE-2026-34089 | HIGH | 7.5 | 0.2% | May 11, 2026 | Vulnerability in Wikimedia Foundation Scribunto. This issue affects Scribunto: from 1.45.0 before 1.45.2. |
| CVE-2026-34088 | HIGH | 7.5 | 0.3% | May 11, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This issue ... |
| CVE-2026-34087 | HIGH | 7.5 | 0.3% | May 11, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation OATHAuth. This issue a... |
| CVE-2026-31247 | HIGH | 7.5 | 0.4% | May 11, 2026 | Docling's JATS XML backend is vulnerable to XML Entity Expansion (XXE) attacks thru 2.61.0. The backend uses etree.parse... |
| CVE-2026-4802 | HIGH | 8 | 1.0% | May 11, 2026 | A flaw was found in Cockpit. This vulnerability allows a remote attacker to achieve arbitrary command execution on the h... |
| CVE-2026-41951 | HIGH | 8.6 | 0.5% | May 11, 2026 | Path traversal vulnerability exists in GROWI v7.5.0 and earlier, which may allow an attacker to execute arbitrary EJS te... |
| CVE-2026-40636 | HIGH | 7.8 | 0.2% | May 11, 2026 | Dell ECS versions 3.8.1.0 through 3.8.1.7 and Dell ObjectScale versions prior to 4.3.0.0, contains a use of hard-coded c... |
| CVE-2026-32658 | HIGH | 8.8 | 0.2% | May 11, 2026 | Dell Automation Platform versions prior to 2.0.0.0, contains a missing authorization vulnerability. A low privileged att... |
| CVE-2026-43500 | HIGH | 7.8 | 92.9% | May 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: rxrpc: Also unshare DATA/RESPONSE packets when page... |
| CVE-2026-6433 | HIGH | 7.3 | 0.8% | May 11, 2026 | The Custom css-js-php WordPress plugin through 2.0.7 does not properly sanitize user input before using it in a SQL quer... |
| CVE-2026-8273 | HIGH | 7.2 | 4.5% | May 11, 2026 | A weakness has been identified in D-Link DNS-320 2.06B01. This impacts the function cgi_set_host/cgi_set_ntp/cgi_fan_con... |
| CVE-2026-8272 | HIGH | 7.2 | 5.6% | May 11, 2026 | A security flaw has been discovered in D-Link DNS-320 2.06B01. This affects the function delete/rename/copy/move/chmod/c... |
| CVE-2026-8271 | HIGH | 7.2 | 4.6% | May 11, 2026 | A vulnerability was identified in D-Link DNS-320 2.06B01. The impacted element is the function cgi_speed/cgi_dhcpd_lease... |
| CVE-2026-8265 | HIGH | 7.2 | 4.4% | May 11, 2026 | A security vulnerability has been detected in Tenda AC6 15.03.06.23. Affected by this issue is the function get_log_file... |
| CVE-2026-8264 | HIGH | 8.8 | 2.9% | May 11, 2026 | A weakness has been identified in Tenda AC6 15.03.06.23. Affected by this vulnerability is the function formWifiApScan o... |
| CVE-2026-8260 | HIGH | 8.8 | 1.0% | May 11, 2026 | A vulnerability was found in D-Link DCS-935L up to 1.10.01. The impacted element is the function SetDeviceSettings of th... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now