2026 CVE Vulnerabilities
51,085 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42575 | HIGH | 7.5 | 0.2% | May 9, 2026 | apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, apko verifi... |
| CVE-2026-42574 | HIGH | 7.5 | 0.4% | May 9, 2026 | apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before versi... |
| CVE-2026-42562 | HIGH | 8.3 | 0.3% | May 9, 2026 | Plainpad is a self hosted note taking app. Prior to version 1.1.1, Plainpad allows a low-privilege authenticated user to... |
| CVE-2026-42246 | HIGH | 7.4 | 0.3% | May 9, 2026 | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4... |
| CVE-2026-42245 | HIGH | 7.5 | 0.4% | May 9, 2026 | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5... |
| CVE-2026-41893 | HIGH | 7.5 | 0.3% | May 9, 2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.25.0, the HTTP login en... |
| CVE-2026-8192 | HIGH | 8.8 | 4.8% | May 9, 2026 | A security flaw has been discovered in Wavlink NU516U1 M16U1_V240425. This vulnerability affects the function wzdap of t... |
| CVE-2026-8191 | HIGH | 8.8 | 5.3% | May 9, 2026 | A vulnerability was identified in Wavlink NU516U1 M16U1_V240425. This affects the function wifi_region of the file /cgi-... |
| CVE-2026-8190 | HIGH | 8.8 | 5.3% | May 9, 2026 | A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. Affected by this issue is the function wan of the file ... |
| CVE-2026-8189 | HIGH | 8.8 | 4.8% | May 9, 2026 | A vulnerability was found in Wavlink NU516U1 M16U1_V240425. Affected by this vulnerability is the function wzdrepeater o... |
| CVE-2026-8188 | HIGH | 8.8 | 5.5% | May 9, 2026 | A vulnerability has been found in Wavlink NU516U1 M16U1_V240425. Affected is the function change_wifi_password of the fi... |
| CVE-2026-8186 | HIGH | 7.5 | 0.5% | May 9, 2026 | A vulnerability was detected in Open5GS up to 2.7.7. This affects the function ogs_sbi_client_send_via_scp_or_sepp in th... |
| CVE-2026-8187 | HIGH | 7.5 | 0.6% | May 9, 2026 | A flaw has been found in Open5GS up to 2.7.7. This impacts the function _gtpv1_u_recv_cb of the file src/upf/gtp-path.c ... |
| CVE-2026-3828 | HIGH | 7.2 | 0.8% | May 9, 2026 | Some Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command executi... |
| CVE-2026-42311 | HIGH | 7.8 | 0.1% | May 9, 2026 | Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could ... |
| CVE-2026-8208 | HIGH | 8.9 | 0.3% | May 9, 2026 | Gibbon versions before v30.0.01 are affected by a local file inclusion vulnerability resulting in RCE by changing the re... |
| CVE-2026-42461 | HIGH | 7.5 | 0.3% | May 9, 2026 | Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.18.0, four GET ... |
| CVE-2026-42301 | HIGH | 7.8 | 0.2% | May 9, 2026 | pyp2spec generates working Fedora RPM spec file for Python projects. Prior to version 0.14.1, pyp2spec was writing PyPI ... |
| CVE-2026-42297 | HIGH | 8.3 | 0.5% | May 9, 2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From ve... |
| CVE-2026-42296 | HIGH | 8.1 | 0.4% | May 9, 2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior t... |
| CVE-2026-42294 | HIGH | 7.5 | 0.6% | May 9, 2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior t... |
| CVE-2026-41163 | HIGH | 7 | 0.3% | May 9, 2026 | bubblewrap is a low-level unprivileged sandboxing tool. From version 0.11.0 to before version 0.11.2, if bubblewrap is i... |
| CVE-2026-8207 | HIGH | 7 | 0.2% | May 9, 2026 | Gibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/gr... |
| CVE-2026-6666 | HIGH | 7.5 | 0.4% | May 9, 2026 | A possible null pointer reference in PgBouncer before 1.25.2 could lead to a crash, if a server sends an error response ... |
| CVE-2026-6664 | HIGH | 7.5 | 0.7% | May 9, 2026 | An integer overflow in network packet parsing code in PgBouncer before 1.25.2 bypasses a boundary check and can lead to ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now