2026 CVE Vulnerabilities
44,067 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-50883 | CRITICAL | 9.6 | 0.4% | Jun 15, 2026 | An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute ... |
| CVE-2026-50880 | CRITICAL | 9.8 | 0.5% | Jun 15, 2026 | An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary cod... |
| CVE-2026-50873 | CRITICAL | 9.8 | 0.4% | Jun 15, 2026 | An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to exec... |
| CVE-2026-50872 | CRITICAL | 9.8 | 0.6% | Jun 15, 2026 | An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitra... |
| CVE-2026-50871 | CRITICAL | 9.8 | 1.6% | Jun 15, 2026 | An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscenc... |
| CVE-2026-50869 | CRITICAL | 9.8 | 0.7% | Jun 15, 2026 | An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplyi... |
| CVE-2026-49952 | CRITICAL | 9.3 | 0.5% | Jun 15, 2026 | Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthentica... |
| CVE-2026-48114 | CRITICAL | 9.8 | 0.4% | Jun 15, 2026 | Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.0.0 and and ab... |
| CVE-2026-45390 | CRITICAL | 9.1 | 0.4% | Jun 15, 2026 | In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working dire... |
| CVE-2026-45388 | CRITICAL | 9.1 | 0.2% | Jun 15, 2026 | In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server,... |
| CVE-2026-39196 | CRITICAL | 9.8 | 0.3% | Jun 15, 2026 | Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in th... |
| CVE-2026-39006 | CRITICAL | 9.8 | 0.5% | Jun 15, 2026 | An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component... |
| CVE-2026-38812 | CRITICAL | 9.8 | 0.4% | Jun 15, 2026 | RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generatio... |
| CVE-2026-38329 | CRITICAL | 9.8 | 0.6% | Jun 15, 2026 | Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoi... |
| CVE-2026-38065 | CRITICAL | 9.8 | 1.3% | Jun 15, 2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ... |
| CVE-2026-38064 | CRITICAL | 9.8 | 1.0% | Jun 15, 2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNu... |
| CVE-2026-38063 | CRITICAL | 9.8 | 1.0% | Jun 15, 2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via... |
| CVE-2026-38062 | CRITICAL | 9.8 | 1.0% | Jun 15, 2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via the rat... |
| CVE-2026-38061 | CRITICAL | 9.8 | 1.0% | Jun 15, 2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volum... |
| CVE-2026-38060 | CRITICAL | 9.8 | 1.0% | Jun 15, 2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin p... |
| CVE-2026-36537 | CRITICAL | 9.8 | 0.5% | Jun 15, 2026 | ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The applica... |
| CVE-2026-30121 | CRITICAL | 9.1 | 0.3% | Jun 15, 2026 | remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability. |
| CVE-2026-30120 | CRITICAL | 9.8 | 0.8% | Jun 15, 2026 | remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability. |
| CVE-2026-9862 | CRITICAL | 9.8 | 1.0% | Jun 15, 2026 | Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd... |
| CVE-2026-52704 | CRITICAL | 10 | 0.3% | Jun 15, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now