2026 CVE Vulnerabilities
51,327 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42231 | HIGH | 8.8 | 0.9% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the xml2js... |
| CVE-2026-42229 | HIGH | 8.8 | 0.3% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the SeaTab... |
| CVE-2026-42226 | HIGH | 7.5 | 0.3% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.33 and 2.17.5, the dynamic-node-parameters e... |
| CVE-2026-42154 | HIGH | 7.5 | 0.8% | May 4, 2026 | Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote ... |
| CVE-2026-42151 | HIGH | 7.5 | 0.4% | May 4, 2026 | Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_... |
| CVE-2026-38751 | HIGH | 7.2 | 0.4% | May 4, 2026 | OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionali... |
| CVE-2026-25863 | HIGH | 8.7 | 0.4% | May 4, 2026 | Conditional Fields for Contact Form 7 WordPress plugin through version 2.7.2 contains an uncontrolled resource consumpti... |
| CVE-2026-43616 | HIGH | 7.8 | 0.2% | May 4, 2026 | Detect-It-Easy prior to 3.21 contains a path traversal vulnerability that allows attackers to write arbitrary files to t... |
| CVE-2026-42088 | HIGH | 8.1 | 0.3% | May 4, 2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2026-42084 | HIGH | 8.1 | 0.3% | May 4, 2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2026-41471 | HIGH | 8.2 | 0.3% | May 4, 2026 | The Easy PayPal Events & Tickets plugin for WordPress before version 1.4 contains an information disclosure vulnerabilit... |
| CVE-2026-37459 | HIGH | 7.5 | 0.4% | May 4, 2026 | An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) v... |
| CVE-2026-32834 | HIGH | 8.7 | 0.4% | May 4, 2026 | Easy PayPal Events & Tickets plugin for WordPress before version 1.4 contains a hardcoded authentication bypass vulnerab... |
| CVE-2026-29004 | HIGH | 8.1 | 0.4% | May 4, 2026 | BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS o... |
| CVE-2026-0073 | HIGH | 8.8 | 0.5% | May 4, 2026 | In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic err... |
| CVE-2026-42440 | HIGH | 7.5 | 0.6% | May 4, 2026 | OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader Versions Affected: before... |
| CVE-2026-42375 | HIGH | 8.8 | 0.5% | May 4, 2026 | D-Link DIR-600L Hardware Revision A1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daem... |
| CVE-2026-42374 | HIGH | 8.8 | 0.5% | May 4, 2026 | D-Link DIR-600L Hardware Revision B1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daem... |
| CVE-2026-42373 | HIGH | 8.8 | 0.5% | May 4, 2026 | D-Link DIR-605L Hardware Revision B2 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet... |
| CVE-2026-42372 | HIGH | 8.8 | 0.3% | May 4, 2026 | D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet... |
| CVE-2026-42079 | HIGH | 8.6 | 0.1% | May 4, 2026 | PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable t... |
| CVE-2026-42075 | HIGH | 8.1 | 0.6% | May 4, 2026 | Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a path traversal vulnerability in ... |
| CVE-2026-37461 | HIGH | 7.5 | 0.3% | May 4, 2026 | An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial ... |
| CVE-2026-29514 | HIGH | 8.8 | 0.8% | May 4, 2026 | NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environ... |
| CVE-2026-25266 | HIGH | 7.8 | 0.1% | May 4, 2026 | Memory corruption while processing IOCTL command when device is in power-save state. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now