2026 CVE Vulnerabilities
51,307 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7788 | HIGH | 7.3 | 0.4% | May 5, 2026 | A security flaw has been discovered in Axle-Bucamp MCP-Docusaurus up to 404bc028e15ec304c9a045528560f4b5f27a17e0. The af... |
| CVE-2026-7785 | HIGH | 7.3 | 1.3% | May 5, 2026 | A security flaw has been discovered in A-G-U-P-T-A wireshark-mcp edaf604416fbc94a201b4043092d4a1b09a12275/400c3da70074f2... |
| CVE-2026-7784 | HIGH | 7.3 | 0.5% | May 5, 2026 | A vulnerability has been found in RTGS2017 NagaAgent up to 5.1.0. This issue affects some unknown processing of the file... |
| CVE-2026-7791 | HIGH | 8.5 | 0.1% | May 4, 2026 | Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpace... |
| CVE-2026-7776 | HIGH | 7.5 | 0.2% | May 4, 2026 | Boundary Community Edition and Boundary Enterprise (“Boundary”) workers are vulnerable to a denial-of-service condition ... |
| CVE-2026-7768 | HIGH | 7.5 | 0.3% | May 4, 2026 | @fastify/accepts-serializer cached serializer-selection results keyed by the request Accept header without a size limit ... |
| CVE-2026-6321 | HIGH | 7.5 | 0.5% | May 4, 2026 | fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize()... |
| CVE-2026-41927 | HIGH | 8.3 | 0.4% | May 4, 2026 | WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains a stack-based buffer overflow vulnerability in the firew... |
| CVE-2026-43964 | HIGH | 7.5 | 0.5% | May 4, 2026 | Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash v... |
| CVE-2026-42237 | HIGH | 8.8 | 0.3% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the fix for GHSA-f3f... |
| CVE-2026-42236 | HIGH | 7.5 | 0.5% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the MCP OAuth client... |
| CVE-2026-42234 | HIGH | 8.8 | 0.4% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated use... |
| CVE-2026-42232 | HIGH | 8.8 | 0.5% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated use... |
| CVE-2026-42231 | HIGH | 8.8 | 0.9% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the xml2js... |
| CVE-2026-42229 | HIGH | 8.8 | 0.3% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the SeaTab... |
| CVE-2026-42226 | HIGH | 7.5 | 0.3% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.33 and 2.17.5, the dynamic-node-parameters e... |
| CVE-2026-42154 | HIGH | 7.5 | 0.8% | May 4, 2026 | Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote ... |
| CVE-2026-42151 | HIGH | 7.5 | 0.4% | May 4, 2026 | Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_... |
| CVE-2026-38751 | HIGH | 7.2 | 0.4% | May 4, 2026 | OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionali... |
| CVE-2026-25863 | HIGH | 8.7 | 0.4% | May 4, 2026 | Conditional Fields for Contact Form 7 WordPress plugin through version 2.7.2 contains an uncontrolled resource consumpti... |
| CVE-2026-43616 | HIGH | 7.8 | 0.2% | May 4, 2026 | Detect-It-Easy prior to 3.21 contains a path traversal vulnerability that allows attackers to write arbitrary files to t... |
| CVE-2026-42088 | HIGH | 8.1 | 0.3% | May 4, 2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2026-42084 | HIGH | 8.1 | 0.3% | May 4, 2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2026-41471 | HIGH | 8.2 | 0.3% | May 4, 2026 | The Easy PayPal Events & Tickets plugin for WordPress before version 1.4 contains an information disclosure vulnerabilit... |
| CVE-2026-37459 | HIGH | 7.5 | 0.4% | May 4, 2026 | An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) v... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now