2026 CVE Vulnerabilities
44,078 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30120 | CRITICAL | 9.8 | 0.8% | Jun 15, 2026 | remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability. |
| CVE-2026-9862 | CRITICAL | 9.8 | 1.0% | Jun 15, 2026 | Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd... |
| CVE-2026-52704 | CRITICAL | 10 | 0.3% | Jun 15, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder a... |
| CVE-2026-5482 | CRITICAL | 9.3 | 0.4% | Jun 15, 2026 | Responsive FileManager's allows an unauthenticated attacker to upload files of any type and extension without restrictio... |
| CVE-2026-49757 | CRITICAL | 9.2 | 0.6% | Jun 15, 2026 | Authentication Bypass by Spoofing vulnerability in team-alembic AshAuthentication allows account takeover of local users... |
| CVE-2026-8935 | CRITICAL | 9.8 | 0.3% | Jun 15, 2026 | The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that i... |
| CVE-2026-11526 | CRITICAL | 9.8 | 1.4% | Jun 14, 2026 | GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments ... |
| CVE-2026-12183 | CRITICAL | 9.8 | 0.5% | Jun 13, 2026 | Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentic... |
| CVE-2026-11624 | CRITICAL | 9.4 | 0.2% | Jun 13, 2026 | The Model Context Protocol has a security warning advising servers to validate the "Origin" header on all incoming conne... |
| CVE-2026-53838 | CRITICAL | 9.8 | 0.2% | Jun 12, 2026 | OpenClaw before 2026.5.27 contains a state mutation vulnerability in node pairing reconnection that allows paired nodes ... |
| CVE-2026-53609 | CRITICAL | 9.1 | 0.2% | Jun 12, 2026 | ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, `apos.util.se... |
| CVE-2026-53519 | CRITICAL | 9.1 | 0.5% | Jun 12, 2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Prior to version 2.0.13,... |
| CVE-2026-46716 | CRITICAL | 9.9 | 0.3% | Jun 12, 2026 | Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.4.0 to be... |
| CVE-2026-41157 | CRITICAL | 9.8 | 0.4% | Jun 12, 2026 | A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger an out-of-bound ... |
| CVE-2026-44990 | CRITICAL | 9.3 | 0.5% | Jun 12, 2026 | ApostropheCMS is an open-source Node.js content management system, and sanitize-html provides a simple HTML sanitizer wi... |
| CVE-2026-53407 | CRITICAL | 9.8 | 0.2% | Jun 12, 2026 | Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.... |
| CVE-2026-50101 | CRITICAL | 9.2 | 0.3% | Jun 12, 2026 | Naxclow devices use a server-side, per-device relay credential that never rotates and is re-issued to the device on each... |
| CVE-2026-28742 | CRITICAL | 9.8 | 0.3% | Jun 12, 2026 | Naxclow devices use a uniform request-signing scheme based on a hard-coded, platform-wide salt embedded in every firmwar... |
| CVE-2026-48558 | CRITICAL | 10 | 0.7% | Jun 12, 2026 | SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the ... |
| CVE-2026-44172 | CRITICAL | 9.1 | 0.6% | Jun 12, 2026 | MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taki... |
| CVE-2026-44170 | CRITICAL | 9.8 | 1.2% | Jun 12, 2026 | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before ... |
| CVE-2026-50086 | CRITICAL | 9.8 | 0.2% | Jun 12, 2026 | The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing ke... |
| CVE-2026-50085 | CRITICAL | 9.8 | 0.3% | Jun 12, 2026 | The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's ... |
| CVE-2026-50083 | CRITICAL | 9.8 | 0.2% | Jun 12, 2026 | The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-... |
| CVE-2026-47691 | CRITICAL | 10 | 0.3% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now