2026 CVE Vulnerabilities
44,088 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6853 | CRITICAL | 9.8 | 0.3% | Jun 12, 2026 | Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe Businesses Industry ... |
| CVE-2026-54133 | CRITICAL | 9.8 | 0.3% | Jun 12, 2026 | jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON doc... |
| CVE-2026-53787 | CRITICAL | 9.8 | 3.7% | Jun 12, 2026 | Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerabili... |
| CVE-2026-47210 | CRITICAL | 9.8 | 0.5% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, a sandbox escape vulnerability in vm2 allows arbi... |
| CVE-2026-47208 | CRITICAL | 10 | 0.5% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability... |
| CVE-2026-47140 | CRITICAL | 10 | 0.5% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangerous Node.js builtins ... |
| CVE-2026-47137 | CRITICAL | 10 | 0.4% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) ... |
| CVE-2026-47131 | CRITICAL | 10 | 0.4% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__... |
| CVE-2026-45674 | CRITICAL | 10 | 0.2% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina... |
| CVE-2026-10557 | CRITICAL | 9.8 | 0.4% | Jun 12, 2026 | The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and a... |
| CVE-2026-11849 | CRITICAL | 9.8 | 0.4% | Jun 12, 2026 | The iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnerability, allowing una... |
| CVE-2026-50628 | CRITICAL | 9.8 | 0.7% | Jun 12, 2026 | A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly all... |
| CVE-2026-50627 | CRITICAL | 9.1 | 0.4% | Jun 12, 2026 | The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tok... |
| CVE-2026-49875 | CRITICAL | 9.8 | 0.5% | Jun 12, 2026 | Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary... |
| CVE-2026-11535 | CRITICAL | 9.4 | 0.2% | Jun 12, 2026 | An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unaut... |
| CVE-2026-48611 | CRITICAL | 9.8 | 0.7% | Jun 12, 2026 | Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or ... |
| CVE-2026-47370 | CRITICAL | 9.9 | 0.8% | Jun 12, 2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability... |
| CVE-2026-47369 | CRITICAL | 9.9 | 0.3% | Jun 12, 2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability... |
| CVE-2026-47367 | CRITICAL | 9.9 | 0.8% | Jun 12, 2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability... |
| CVE-2026-47365 | CRITICAL | 9.9 | 0.4% | Jun 12, 2026 | Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated... |
| CVE-2026-45060 | CRITICAL | 9.8 | 0.4% | Jun 11, 2026 | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/progress_video.php en... |
| CVE-2026-42846 | CRITICAL | 9.8 | 0.6% | Jun 11, 2026 | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature ... |
| CVE-2026-49060 | CRITICAL | 9.8 | 0.5% | Jun 11, 2026 | Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This iss... |
| CVE-2026-42647 | CRITICAL | 9.3 | 1.3% | Jun 11, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport ... |
| CVE-2026-39494 | CRITICAL | 9.3 | 0.4% | Jun 11, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Produc... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now