2026 CVE Vulnerabilities
51,238 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35397 | HIGH | 8.8 | 0.6% | May 5, 2026 | Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerabili... |
| CVE-2026-34596 | HIGH | 7 | 0.1% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a Time-of... |
| CVE-2026-34464 | HIGH | 8.8 | 0.2% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipe... |
| CVE-2026-34462 | HIGH | 7.8 | 0.2% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, several P... |
| CVE-2026-34461 | HIGH | 7.8 | 0.2% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieI... |
| CVE-2026-34459 | HIGH | 8.8 | 0.1% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieS... |
| CVE-2026-34458 | HIGH | 8.8 | 0.3% | May 5, 2026 | Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI in... |
| CVE-2026-33975 | HIGH | 8.3 | 0.2% | May 5, 2026 | Twenty is an open source CRM built with NestJS (Node.js). In versions 1.18.0 and earlier, the SSRF protection in twenty-... |
| CVE-2026-33489 | HIGH | 7.5 | 0.4% | May 5, 2026 | CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL s... |
| CVE-2026-33324 | HIGH | 8.8 | 0.6% | May 5, 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the T... |
| CVE-2026-33190 | HIGH | 7.5 | 0.4% | May 5, 2026 | CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tsig plugin can be bypassed on non-plain-D... |
| CVE-2026-32936 | HIGH | 7.5 | 0.7% | May 5, 2026 | CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts over... |
| CVE-2026-32934 | HIGH | 7.5 | 0.5% | May 5, 2026 | CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven i... |
| CVE-2026-7855 | HIGH | 7.2 | 1.1% | May 5, 2026 | A vulnerability was detected in D-Link DI-8100 16.07.26A1. Affected by this issue is the function tggl_asp of the file /... |
| CVE-2026-42997 | HIGH | 7.7 | 0.4% | May 5, 2026 | An issue was discovered in idrac in OpenStack Ironic before 35.0.1. During import, a user invoking molds can request aut... |
| CVE-2026-30923 | HIGH | 7.5 | 0.4% | May 5, 2026 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsec... |
| CVE-2026-7851 | HIGH | 7.3 | 4.1% | May 5, 2026 | A vulnerability was identified in D-Link DI-8100 16.07.26A1. This affects the function sprintf of the file yyxz.asp. The... |
| CVE-2026-25589 | HIGH | 8.8 | 1.4% | May 5, 2026 | RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module ... |
| CVE-2026-25588 | HIGH | 8.8 | 1.0% | May 5, 2026 | RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does no... |
| CVE-2026-25243 | HIGH | 8.8 | 3.0% | May 5, 2026 | Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not proper... |
| CVE-2026-23631 | HIGH | 8.1 | 1.8% | May 5, 2026 | Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacke... |
| CVE-2026-23479 | HIGH | 8.8 | 1.3% | May 5, 2026 | Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not han... |
| CVE-2026-7865 | HIGH | 7.4 | 0.8% | May 5, 2026 | A hidden console command is vulnerable to command injection flaw when control characters are passed to its second argume... |
| CVE-2026-7412 | HIGH | 8.6 | 0.5% | May 5, 2026 | In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, the Operation Delegation feature fails to validat... |
| CVE-2026-43070 | HIGH | 7.8 | 0.1% | May 5, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Reset register ID for BPF_END value tracking ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now