2026 CVE Vulnerabilities
51,117 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42271 | HIGH | 8.8 | 80.2% | May 8, 2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before vers... |
| CVE-2026-42261 | HIGH | 7.1 | 0.2% | May 8, 2026 | PromptHub is an all-in-one AI toolbox for prompt, skill, and agent management. From version 0.4.9 to before version 0.5.... |
| CVE-2026-42203 | HIGH | 8.8 | 0.4% | May 8, 2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.80.5 to before vers... |
| CVE-2026-8128 | HIGH | 7.3 | 0.3% | May 8, 2026 | A vulnerability was found in SourceCodester SUP Online Shopping 1.0. The affected element is an unknown function of the ... |
| CVE-2026-8126 | HIGH | 7.3 | 0.3% | May 8, 2026 | A flaw has been found in SourceCodester Comment System 1.0. This issue affects some unknown processing of the file post_... |
| CVE-2026-6411 | HIGH | 7.3 | 0.2% | May 7, 2026 | This vulnerability, in the MAXHUB Pivot client application versions prior to v1.36.2, may allow an attacker to obtain e... |
| CVE-2026-8112 | HIGH | 8.8 | 2.9% | May 7, 2026 | A vulnerability was found in 8421bit MiniClaw up to 223c16a1088e138838dcbd18cd65a37c35ac5a84. Affected is the function e... |
| CVE-2026-7541 | HIGH | 7.5 | 0.4% | May 7, 2026 | A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to... |
| CVE-2026-42826 | HIGH | 7.5 | 0.8% | May 7, 2026 | Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose i... |
| CVE-2026-41105 | HIGH | 8.1 | 0.8% | May 7, 2026 | Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges ove... |
| CVE-2026-40213 | HIGH | 7.4 | 0.2% | May 7, 2026 | OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This un... |
| CVE-2026-34327 | HIGH | 8.2 | 0.6% | May 7, 2026 | Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attac... |
| CVE-2026-33111 | HIGH | 7.5 | 1.1% | May 7, 2026 | Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) all... |
| CVE-2026-26164 | HIGH | 7.5 | 0.8% | May 7, 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz... |
| CVE-2026-26129 | HIGH | 7.5 | 1.1% | May 7, 2026 | Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthoriz... |
| CVE-2026-8098 | HIGH | 7.3 | 0.3% | May 7, 2026 | A security vulnerability has been detected in code-projects Feedback System 1.0. Impacted is an unknown function of the ... |
| CVE-2026-42449 | HIGH | 8.5 | 0.2% | May 7, 2026 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. In ve... |
| CVE-2026-42047 | HIGH | 8.6 | 0.4% | May 7, 2026 | Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orche... |
| CVE-2026-8087 | HIGH | 7.8 | 0.2% | May 7, 2026 | A security flaw has been discovered in OSGeo gdal up to 3.13.0dev-4. Impacted is the function GDnentries of the file frm... |
| CVE-2026-42501 | HIGH | 7.5 | 0.2% | May 7, 2026 | A malicious module proxy can exploit a flaw in the go command's validation of module checksums to bypass checksum databa... |
| CVE-2026-42499 | HIGH | 7.5 | 0.8% | May 7, 2026 | Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322. |
| CVE-2026-42239 | HIGH | 8.1 | 0.3% | May 7, 2026 | Budibase is an open-source low-code platform. Prior to version 3.35.10, the budibase:auth cookie containing the JWT sess... |
| CVE-2026-39836 | HIGH | 7.5 | 0.6% | May 7, 2026 | The Dial and LookupPort functions panic on Windows when provided with an input containing a NUL (0). |
| CVE-2026-39820 | HIGH | 7.5 | 0.8% | May 7, 2026 | Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion... |
| CVE-2026-33814 | HIGH | 7.5 | 0.8% | May 7, 2026 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now