2026 CVE Vulnerabilities
51,208 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-43074 | HIGH | 7.8 | 0.1% | May 6, 2026 | In the Linux kernel, the following vulnerability has been resolved: eventpoll: defer struct eventpoll free to RCU grace... |
| CVE-2026-1719 | HIGH | 7.5 | 0.3% | May 6, 2026 | The Gravity Bookings Premium plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2... |
| CVE-2026-7841 | HIGH | 8.8 | 0.6% | May 6, 2026 | A remote code execution vulnerability exists in Notification Settings on GeoVision GV-ASWeb 6.2.0. An authenticated user... |
| CVE-2026-7332 | HIGH | 7.2 | 0.4% | May 6, 2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Stored Cross-S... |
| CVE-2026-23928 | HIGH | 7.3 | 0.3% | May 6, 2026 | The Item history widget (in Zabbix 7.0+) or the Plain text widget (in Zabbix 6.0) can execute injected JavaScript when H... |
| CVE-2026-23926 | HIGH | 7.3 | 0.3% | May 6, 2026 | An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by... |
| CVE-2026-7573 | HIGH | 7.7 | 0.3% | May 6, 2026 | An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 a... |
| CVE-2026-40110 | HIGH | 7.3 | 0.3% | May 5, 2026 | Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation... |
| CVE-2026-40075 | HIGH | 7.5 | 0.6% | May 5, 2026 | OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8... |
| CVE-2026-40068 | HIGH | 8.8 | 0.3% | May 5, 2026 | In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir f... |
| CVE-2026-39852 | HIGH | 8.2 | 0.4% | May 5, 2026 | Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3... |
| CVE-2026-39849 | HIGH | 8.8 | 1.0% | May 5, 2026 | Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. In versions before 6.6.1,... |
| CVE-2026-39383 | HIGH | 7.2 | 0.2% | May 5, 2026 | Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access c... |
| CVE-2026-7857 | HIGH | 7.3 | 4.2% | May 5, 2026 | A vulnerability has been found in D-Link DI-8100 16.07.26A1. This vulnerability affects the function sprintf of the file... |
| CVE-2026-7856 | HIGH | 7.3 | 4.6% | May 5, 2026 | A flaw has been found in D-Link DI-8100 16.07.26A1. This affects an unknown part of the file /url_member.asp of the comp... |
| CVE-2026-44331 | HIGH | 8.1 | 0.5% | May 5, 2026 | In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerability in sqltab_fetch_clients_cb() in contrib/mod_wrap... |
| CVE-2026-40280 | HIGH | 7.5 | 0.5% | May 5, 2026 | Gotenberg is an API-based document conversion tool. In versions 8.30.1 and earlier, the default private-IP deny-lists fo... |
| CVE-2026-35397 | HIGH | 8.8 | 0.6% | May 5, 2026 | Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerabili... |
| CVE-2026-34596 | HIGH | 7 | 0.1% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a Time-of... |
| CVE-2026-34464 | HIGH | 8.8 | 0.2% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipe... |
| CVE-2026-34462 | HIGH | 7.8 | 0.2% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, several P... |
| CVE-2026-34461 | HIGH | 7.8 | 0.2% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieI... |
| CVE-2026-34459 | HIGH | 8.8 | 0.1% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieS... |
| CVE-2026-34458 | HIGH | 8.8 | 0.3% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI in... |
| CVE-2026-33975 | HIGH | 8.3 | 0.2% | May 5, 2026 | Twenty is an open source CRM built with NestJS (Node.js). In versions 1.18.0 and earlier, the SSRF protection in twenty-... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now