2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9503 | LOW | 3.3 | 0.1% | May 25, 2026 | A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function dwg_next_entity of the file sr... |
| CVE-2026-9501 | LOW | 3.3 | 0.1% | May 25, 2026 | A vulnerability was determined in GNU LibreDWG up to 0.14. The impacted element is the function decompress_R2004_section... |
| CVE-2026-48852 | LOW | 3.7 | 0.3% | May 25, 2026 | PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification. |
| CVE-2026-48851 | LOW | 3.1 | 0.2% | May 25, 2026 | PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not c... |
| CVE-2026-9485 | LOW | 3.5 | 0.2% | May 25, 2026 | A vulnerability was identified in SourceCodester Student Grades Management System 1.0. Affected by this issue is some un... |
| CVE-2026-48847 | LOW | 3.7 | 0.4% | May 25, 2026 | Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redi... |
| CVE-2026-9471 | LOW | 3.5 | 0.2% | May 25, 2026 | A vulnerability was detected in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This ... |
| CVE-2026-9414 | LOW | 3.5 | 0.2% | May 25, 2026 | A security flaw has been discovered in SourceCodester Indian Invoicing System up to 0.x/1.0. The impacted element is an ... |
| CVE-2026-48832 | LOW | 3.5 | 0.2% | May 24, 2026 | action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirect vulnerability. |
| CVE-2026-9398 | LOW | 3.1 | 0.3% | May 24, 2026 | A security vulnerability has been detected in Besen BS20 EV Charging Station up to 20260426. This affects an unknown par... |
| CVE-2026-9396 | LOW | 3.7 | 0.3% | May 24, 2026 | A security flaw has been discovered in Besen BS20 EV Charging Station up to 20260426. Affected by this vulnerability is ... |
| CVE-2026-9395 | LOW | 3.5 | 0.2% | May 24, 2026 | A vulnerability was identified in Besen BS20 EV Charging Station up to 20260426. Affected is an unknown function of the ... |
| CVE-2026-9394 | LOW | 3.1 | 0.2% | May 24, 2026 | A vulnerability was determined in Besen BS20 EV Charging Station up to 20260426. This impacts an unknown function of the... |
| CVE-2026-9377 | LOW | 2.4 | 0.2% | May 24, 2026 | A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of... |
| CVE-2026-9370 | LOW | 3.7 | 0.2% | May 24, 2026 | A weakness has been identified in ulisesbocchio jasypt-spring-boot up to 3.0.5/4.0.4. Affected by this vulnerability is ... |
| CVE-2026-9357 | LOW | 3.5 | 0.3% | May 24, 2026 | A vulnerability was found in vBulletin 6.x. This impacts an unknown function of the component Login. Performing a manipu... |
| CVE-2026-9306 | LOW | 3.7 | 0.3% | May 23, 2026 | A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourne... |
| CVE-2026-39824 | LOW | 3.3 | 0.1% | May 22, 2026 | NewNTUnicodeString does not check for string length overflow. When provided with a string that overflows the maximum siz... |
| CVE-2026-39967 | LOW | 3.1 | 0.2% | May 22, 2026 | TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the bot engine's the findResult query does not filter r... |
| CVE-2026-9249 | LOW | 3.1 | 0.1% | May 22, 2026 | Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the pr... |
| CVE-2026-9248 | LOW | 2.6 | 0.1% | May 22, 2026 | Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write acce... |
| CVE-2026-9247 | LOW | 2.4 | 0.2% | May 22, 2026 | Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissi... |
| CVE-2026-8477 | LOW | 2.7 | 0.2% | May 22, 2026 | Improper enforcement of the sealed-entry workflow in the entry sensitive-data retrieval feature in Devolutions Server al... |
| CVE-2026-25608 | LOW | 2.3 | 0.2% | May 22, 2026 | STER uses unencrypted TCP traffic to transmit data over the network. It allows an attacker to conduct a Man-In-The-Middl... |
| CVE-2026-7837 | LOW | 3.7 | 0.2% | May 21, 2026 | A time-of-check time-of-use (TOCTOU) condition in the ad_flush function in Netatalk 3.0.0 through 4.4.2 involves root-pr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now