2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47337 | LOW | 3.3 | 0.1% | May 28, 2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET... |
| CVE-2026-47336 | LOW | 3.3 | 0.1% | May 28, 2026 | Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor AF_INET/AF_INET6 so... |
| CVE-2026-47330 | LOW | 3.3 | 0.1% | May 28, 2026 | Ubuntu Linux 6.8, 7.17 and 7.0 contain AppArmor SAUCE patches which can, under certain circumstances, use an uninitializ... |
| CVE-2026-47329 | LOW | 3.3 | 0.1% | May 28, 2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches which fail to validate invalid sizes of the name field in AppAmor n... |
| CVE-2026-47327 | LOW | 3.3 | 0.1% | May 28, 2026 | Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AppArmo... |
| CVE-2026-45076 | LOW | 2.7 | 0.4% | May 28, 2026 | Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers ... |
| CVE-2026-48524 | LOW | 3.7 | 0.2% | May 28, 2026 | PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP r... |
| CVE-2026-48156 | LOW | 3.3 | 0.1% | May 28, 2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can cr... |
| CVE-2026-9828 | LOW | 2.9 | 0.4% | May 28, 2026 | Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-... |
| CVE-2026-49009 | LOW | 3.1 | 0.5% | May 27, 2026 | Northern.tech Mender Server v4.1.0, v4.0.1 and below, and fixed in v4.1.1 and v4.0.2 allows Directory Traversal. |
| CVE-2026-33552 | LOW | 3.7 | 0.3% | May 27, 2026 | Northern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control. |
| CVE-2026-44474 | LOW | 3.7 | 0.1% | May 27, 2026 | Ella Core is a 5G core designed for private networks. Prior to 1.10.0, Ella Core didn't enforce security rules on concur... |
| CVE-2026-9712 | LOW | 3.8 | 0.2% | May 27, 2026 | When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, ra... |
| CVE-2026-46057 | LOW | 3.3 | 0.1% | May 27, 2026 | In the Linux kernel, the following vulnerability has been resolved: landlock: Fix LOG_SUBDOMAINS_OFF inheritance across... |
| CVE-2026-42791 | LOW | 3.7 | 0.3% | May 27, 2026 | Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows forged OCSP responses... |
| CVE-2026-9608 | LOW | 2.4 | 0.2% | May 27, 2026 | A vulnerability was determined in QianFox FoxCMS up to 1.2.6. The impacted element is an unknown function of the file /T... |
| CVE-2026-9567 | LOW | 3.3 | 0.1% | May 26, 2026 | A security flaw has been discovered in GPAC up to 2.4.0. Affected is the function MergeFragment of the file src/isomedia... |
| CVE-2026-42448 | LOW | 3.5 | 0.2% | May 26, 2026 | Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. Prior to 0.2... |
| CVE-2026-9564 | LOW | 2.4 | 0.2% | May 26, 2026 | A vulnerability was found in SourceCodester/oretnom23 Hospitals Patient Records Management System 1.0. The impacted elem... |
| CVE-2026-47716 | LOW | 3.1 | 0.1% | May 26, 2026 | Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, In affected versions, the issue list view authorizes acces... |
| CVE-2026-47715 | LOW | 3.1 | 0.2% | May 26, 2026 | Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink issue event pages accept a direct event identifier... |
| CVE-2026-44410 | LOW | 3.8 | 0.1% | May 26, 2026 | This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended... |
| CVE-2026-9530 | LOW | 3.3 | 0.1% | May 26, 2026 | A weakness has been identified in GNU LibreDWG up to 0.14. The impacted element is the function read_2004_compressed_sec... |
| CVE-2026-9529 | LOW | 3.3 | 0.1% | May 26, 2026 | A security flaw has been discovered in GNU LibreDWG up to 0.14. The affected element is the function match_BLOCK_HEADER ... |
| CVE-2026-9504 | LOW | 3.3 | 0.2% | May 25, 2026 | A weakness has been identified in GNU LibreDWG up to 0.14. Affected is the function bit_convert_TU of the file programs/... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now