2026 CVE Vulnerabilities
51,120 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-33814 | HIGH | 7.5 | 0.8% | May 7, 2026 | When processing HTTP/2 SETTINGS frames, transport will enter an infinite loop of writing CONTINUATION frames if it recei... |
| CVE-2026-33811 | HIGH | 7.5 | 0.8% | May 7, 2026 | When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a... |
| CVE-2026-8086 | HIGH | 7.8 | 0.2% | May 7, 2026 | A vulnerability was identified in OSGeo gdal up to 3.13.0dev-4. This issue affects the function SWnentries of the file f... |
| CVE-2026-8083 | HIGH | 7.3 | 0.3% | May 7, 2026 | A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the... |
| CVE-2026-44244 | HIGH | 7.8 | 0.2% | May 7, 2026 | GitPython is a python library used to interact with Git repositories. Prior to version 3.1.49, GitConfigParser.set_value... |
| CVE-2026-44243 | HIGH | 7.1 | 0.4% | May 7, 2026 | GitPython is a python library used to interact with Git repositories. Prior to version 3.1.48, a vulnerability in GitPyt... |
| CVE-2026-42215 | HIGH | 8.8 | 0.7% | May 7, 2026 | GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitP... |
| CVE-2026-42214 | HIGH | 7.8 | 0.2% | May 7, 2026 | Notepad Next is a cross-platform, reimplementation of Notepad++. Prior to version 0.14, NotepadNext's detectLanguageFrom... |
| CVE-2026-41906 | HIGH | 7.1 | 0.2% | May 7, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.214, the Change ... |
| CVE-2026-41905 | HIGH | 7.7 | 0.2% | May 7, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, Helper::san... |
| CVE-2026-41904 | HIGH | 7.6 | 0.2% | May 7, 2026 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user with... |
| CVE-2026-41653 | HIGH | 7 | 0.4% | May 7, 2026 | BentoPDF is a client-side PDF toolkit that is self hostable. Prior to version 2.8.3, a cross-site scripting vulnerabilit... |
| CVE-2026-6973 | HIGH | 7.2 | 34.5% | May 7, 2026 | An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authentic... |
| CVE-2026-5786 | HIGH | 8.8 | 0.7% | May 7, 2026 | An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote... |
| CVE-2026-44349 | HIGH | 7.1 | 0.3% | May 7, 2026 | Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.5, processFuzzySearch in server/resource/resource_finda... |
| CVE-2026-42011 | HIGH | 7.4 | 0.5% | May 7, 2026 | A flaw was found in gnutls. This vulnerability occurs because permitted name constraints were incorrectly ignored when p... |
| CVE-2026-41688 | HIGH | 7.7 | 0.2% | May 7, 2026 | Wallos is an open-source, self-hostable personal subscription tracker. In versions 4.8.4 and prior, the incomplete SSRF ... |
| CVE-2026-41654 | HIGH | 8.1 | 0.4% | May 7, 2026 | Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (de... |
| CVE-2026-41505 | HIGH | 8.7 | 0.3% | May 7, 2026 | RELATE is a web-based courseware package. Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation ... |
| CVE-2026-41422 | HIGH | 8.3 | 0.3% | May 7, 2026 | Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.4, the /aggregate/:typename endpoint accepted column an... |
| CVE-2026-41554 | HIGH | 7.1 | 0.1% | May 7, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricks Builder all... |
| CVE-2026-41490 | HIGH | 8.3 | 0.3% | May 7, 2026 | Dagster is an orchestration platform for the development, production, and observation of data assets. Prior to Dagster C... |
| CVE-2026-30495 | HIGH | 8.8 | 0.2% | May 7, 2026 | The Optoma CinemaX P2 projector (firmware TVOS-04.24.010.04.01, Android 8.0.0) exposes Android Debug Bridge (ADB) on TCP... |
| CVE-2026-8093 | HIGH | 8.1 | 0.3% | May 7, 2026 | Memory safety bugs present in Firefox 150.0.1. Some of these bugs showed evidence of memory corruption and we presume th... |
| CVE-2026-8092 | HIGH | 8.1 | 0.4% | May 7, 2026 | Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now