2026 CVE Vulnerabilities
44,067 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35268 | CRITICAL | 9.9 | 0.4% | Jun 17, 2026 | Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Core). Supported versions that ar... |
| CVE-2026-35263 | CRITICAL | 9.9 | 0.3% | Jun 17, 2026 | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are... |
| CVE-2026-48777 | CRITICAL | 9.3 | 0.4% | Jun 16, 2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable, 1.4.0-beta and 1.4.1... |
| CVE-2026-22313 | CRITICAL | 9.1 | 0.9% | Jun 16, 2026 | The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting a... |
| CVE-2026-0126 | CRITICAL | 9.8 | 0.3% | Jun 16, 2026 | In WC-Radio, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execu... |
| CVE-2026-53861 | CRITICAL | 9.8 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.5.6 contains an allowlist bypass vulnerability in the macOS Swift exec feature that misses combined... |
| CVE-2026-53776 | CRITICAL | 9.3 | 0.4% | Jun 16, 2026 | Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by... |
| CVE-2026-12316 | CRITICAL | 9.1 | 0.2% | Jun 16, 2026 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
| CVE-2026-12315 | CRITICAL | 9.1 | 0.3% | Jun 16, 2026 | Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thund... |
| CVE-2026-12304 | CRITICAL | 9.1 | 0.2% | Jun 16, 2026 | Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 152, Firefox ESR... |
| CVE-2026-12297 | CRITICAL | 9.6 | 0.4% | Jun 16, 2026 | Sandbox escape due to incorrect boundary conditions in the Networking component. This vulnerability was fixed in Firefox... |
| CVE-2026-12296 | CRITICAL | 9.6 | 0.4% | Jun 16, 2026 | Sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 152, Firefox ESR 1... |
| CVE-2026-12295 | CRITICAL | 9.6 | 0.4% | Jun 16, 2026 | Sandbox escape in the DOM: Navigation component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefo... |
| CVE-2026-12294 | CRITICAL | 9.6 | 0.4% | Jun 16, 2026 | Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox E... |
| CVE-2026-12293 | CRITICAL | 9.8 | 0.3% | Jun 16, 2026 | Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
| CVE-2026-40750 | CRITICAL | 9.9 | 0.3% | Jun 16, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Sh... |
| CVE-2026-52715 | CRITICAL | 9.3 | 0.3% | Jun 16, 2026 | Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions. |
| CVE-2026-49774 | CRITICAL | 9.9 | 0.3% | Jun 16, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inc... |
| CVE-2026-49772 | CRITICAL | 9.3 | 0.2% | Jun 16, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / Stell... |
| CVE-2026-39574 | CRITICAL | 9.3 | 0.2% | Jun 16, 2026 | Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions. |
| CVE-2026-9261 | CRITICAL | 9.8 | 0.2% | Jun 16, 2026 | Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier |
| CVE-2026-9260 | CRITICAL | 9.8 | 0.2% | Jun 16, 2026 | Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier |
| CVE-2026-9259 | CRITICAL | 9.8 | 0.2% | Jun 16, 2026 | Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier |
| CVE-2026-9258 | CRITICAL | 9.8 | 0.3% | Jun 16, 2026 | Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier |
| CVE-2026-48853 | CRITICAL | 9.2 | 0.6% | Jun 15, 2026 | Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grp... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now