2026 CVE Vulnerabilities
51,085 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41705 | HIGH | 8.6 | 0.4% | May 9, 2026 | Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized... |
| CVE-2026-42455 | HIGH | 8.8 | 0.5% | May 9, 2026 | Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In ve... |
| CVE-2026-42453 | HIGH | 8.7 | 1.2% | May 8, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v... |
| CVE-2026-42452 | HIGH | 8.1 | 0.3% | May 8, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v... |
| CVE-2026-42352 | HIGH | 8.6 | 0.5% | May 8, 2026 | pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23... |
| CVE-2026-42351 | HIGH | 7.5 | 0.5% | May 8, 2026 | pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23... |
| CVE-2026-42345 | HIGH | 7.7 | 0.2% | May 8, 2026 | FastGPT is an AI Agent building platform. In versions 4.14.11 and prior, FastGPT's isInternalAddress() function in packa... |
| CVE-2026-42339 | HIGH | 7.1 | 0.3% | May 8, 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. In versions 0.1... |
| CVE-2026-42224 | HIGH | 7.6 | 0.3% | May 8, 2026 | ipl/web is a set of common web components for php projects. Prior to versions 0.13.1 and 0.10.3, the vulnerability allow... |
| CVE-2026-41432 | HIGH | 8.2 | 0.3% | May 8, 2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to versio... |
| CVE-2026-42286 | HIGH | 8.4 | 0.2% | May 8, 2026 | Emlog is an open source website building system. Prior to version 2.6.11, missing CSRF protection in critical admin func... |
| CVE-2026-42212 | HIGH | 7.1 | 0.3% | May 8, 2026 | SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.... |
| CVE-2026-42205 | HIGH | 8.8 | 0.3% | May 8, 2026 | Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken access control vulne... |
| CVE-2026-41486 | HIGH | 8.8 | 0.5% | May 8, 2026 | Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension typ... |
| CVE-2026-7807 | HIGH | 8.8 | 0.3% | May 8, 2026 | SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary... |
| CVE-2026-42189 | HIGH | 7.5 | 0.5% | May 8, 2026 | Russh is a Rust SSH client & server library. Prior to version 0.60.1, a pre-authentication denial-of-service vulnerabili... |
| CVE-2026-29203 | HIGH | 8.8 | 0.5% | May 8, 2026 | A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on ... |
| CVE-2026-29202 | HIGH | 8.8 | 0.8% | May 8, 2026 | Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution... |
| CVE-2026-29201 | HIGH | 8.6 | 0.4% | May 8, 2026 | Insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause arbitrary f... |
| CVE-2026-6659 | HIGH | 7.5 | 0.4% | May 8, 2026 | Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function ... |
| CVE-2026-44499 | HIGH | 8.7 | 0.4% | May 8, 2026 | ZEBRA is a Zcash node written entirely in Rust. Prior to version 4.4.0, a composite denial-of-service vulnerability in Z... |
| CVE-2026-43967 | HIGH | 7.5 | 0.6% | May 8, 2026 | Inefficient Algorithmic Complexity vulnerability in absinthe-graphql absinthe allows unauthenticated denial of service v... |
| CVE-2026-42793 | HIGH | 7.5 | 0.6% | May 8, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in absinthe-graphql absinthe allows unauthenticated d... |
| CVE-2026-42353 | HIGH | 8.2 | 0.4% | May 8, 2026 | i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno... |
| CVE-2026-41886 | HIGH | 7.5 | 0.1% | May 8, 2026 | locize is a localization platform that connects code and i18n setup. Prior to version 4.0.21, the locize client SDK regi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now