2026 CVE Vulnerabilities
51,132 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8092 | HIGH | 8.1 | 0.4% | May 7, 2026 | Memory safety bugs present in Firefox ESR 115.35.1, Firefox ESR 140.10.1 and Firefox 150.0.1. Some of these bugs showed ... |
| CVE-2026-8090 | HIGH | 7.3 | 0.3% | May 7, 2026 | Use-after-free in the DOM: Networking component. This vulnerability was fixed in Firefox 150.0.2, Firefox ESR 140.10.2, ... |
| CVE-2026-6002 | HIGH | 8.8 | 0.3% | May 7, 2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in DivvyDrive Information Te... |
| CVE-2026-5784 | HIGH | 8.8 | 0.3% | May 7, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Informa... |
| CVE-2026-42285 | HIGH | 7.5 | 0.4% | May 7, 2026 | GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.4.0, a... |
| CVE-2026-41644 | HIGH | 7.1 | 0.3% | May 7, 2026 | monetr is a budgeting application for recurring expenses. Prior to version 1.12.5, a server-side request forgery (SSRF) ... |
| CVE-2026-41643 | HIGH | 7.5 | 0.5% | May 7, 2026 | GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.... |
| CVE-2026-41642 | HIGH | 7.5 | 0.5% | May 7, 2026 | GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.3.0, a... |
| CVE-2026-3953 | HIGH | 8.8 | 0.3% | May 7, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gosoft Software In... |
| CVE-2026-33588 | HIGH | 8.1 | 0.2% | May 7, 2026 | Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to cr... |
| CVE-2026-28201 | HIGH | 7.8 | 0.1% | May 7, 2026 | An improper input validation, together with an overly permissive default CORS configuration in Open Notebook v1.8.1 allo... |
| CVE-2026-6805 | HIGH | 7.5 | 0.2% | May 7, 2026 | Vulnerability on the external sharing feature in Cryptobox allows an attacker knowing a sharing link URL to retrieve inf... |
| CVE-2026-44407 | HIGH | 7.5 | 0.3% | May 7, 2026 | A remote denial-of-service vulnerability exists in the ZTE Cloud PC client uSmartview, which may lead to memory corrupti... |
| CVE-2026-4430 | HIGH | 7.8 | 0.1% | May 7, 2026 | Out-of-bounds write vulnerability in The Document Foundation LibreOffice via crafted OOXML documents with mismatched enc... |
| CVE-2026-44406 | HIGH | 7.8 | 0.2% | May 7, 2026 | ZTE Cloud PC client uSmartView contains a DLL hijacking vulnerability; since uSmartViewServiceAgent.exe runs with SYSTEM... |
| CVE-2026-8063 | HIGH | 7.1 | 0.2% | May 7, 2026 | An authenticated user can crash mongod when running $rankFusion or $scoreFusion with an empty pipeline on a view. When ... |
| CVE-2026-7252 | HIGH | 8.1 | 0.9% | May 7, 2026 | The WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance plugin for WordPress... |
| CVE-2026-6692 | HIGH | 8.8 | 0.8% | May 7, 2026 | The Slider Revolution plugin for WordPress is vulnerable to Arbitrary File Upload in versions 7.0.0 to 7.0.10 via the '_... |
| CVE-2026-4348 | HIGH | 7.5 | 0.4% | May 7, 2026 | The BetterDocs Pro plugin for WordPress is vulnerable to SQL Injection via the `get_current_letter_docs` and `docs_sort_... |
| CVE-2026-41641 | HIGH | 7.2 | 1.8% | May 7, 2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t... |
| CVE-2026-41413 | HIGH | 7.7 | 0.3% | May 7, 2026 | Istio is an open platform to connect, manage, and secure microservices. Prior to versions 1.28.6 and 1.29.2, when a Requ... |
| CVE-2026-41143 | HIGH | 8.8 | 0.3% | May 7, 2026 | YesWiki is a wiki system written in PHP. Prior to version 4.6.1, YesWiki bazar module contains a SQL injection vulnerabi... |
| CVE-2026-41139 | HIGH | 8.8 | 0.6% | May 7, 2026 | Math.js is an extensive math library for JavaScript and Node.js. From version 13.1.0 to before version 15.2.0, arbitrary... |
| CVE-2026-44602 | HIGH | 7.5 | 0.3% | May 7, 2026 | Tor before 0.4.9.7 has a NULL pointer dereference when a CERT cell is received out of order, aka TROVE-2026-006. |
| CVE-2026-44601 | HIGH | 7.5 | 0.3% | May 7, 2026 | Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close o... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now