2026 CVE Vulnerabilities
44,088 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12027 | CRITICAL | 9.6 | 0.2% | Jun 11, 2026 | Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had comp... |
| CVE-2026-41005 | CRITICAL | 9 | 0.1% | Jun 11, 2026 | Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML s... |
| CVE-2026-49973 | CRITICAL | 9.4 | 0.5% | Jun 11, 2026 | Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remot... |
| CVE-2026-47174 | CRITICAL | 9.5 | 0.3% | Jun 11, 2026 | In Duck Site before version 1.0.1, the repository has a deploy workflow that runs after the build workflow completes. Th... |
| CVE-2026-47172 | CRITICAL | 9.5 | 0.3% | Jun 11, 2026 | Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, the r... |
| CVE-2026-45177 | CRITICAL | 9.1 | 0.5% | Jun 11, 2026 | Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication... |
| CVE-2026-49261 | CRITICAL | 9.8 | 1.6% | Jun 11, 2026 | MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17,... |
| CVE-2026-9648 | CRITICAL | 9.1 | 0.2% | Jun 11, 2026 | The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certi... |
| CVE-2026-11839 | CRITICAL | 9.9 | 0.3% | Jun 11, 2026 | Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows ... |
| CVE-2026-38581 | CRITICAL | 9.8 | 0.3% | Jun 11, 2026 | SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitra... |
| CVE-2026-7852 | CRITICAL | 9.8 | 0.4% | Jun 11, 2026 | Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclu... |
| CVE-2026-11561 | CRITICAL | 9.8 | 0.4% | Jun 11, 2026 | Improper neutralization of special elements used in an expression language statement ('expression language injection') v... |
| CVE-2026-4764 | CRITICAL | 9.4 | 0.2% | Jun 11, 2026 | A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform all... |
| CVE-2026-41699 | CRITICAL | 9.8 | 0.4% | Jun 11, 2026 | Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An a... |
| CVE-2026-35273 | CRITICAL | 9.8 | 92.3% | Jun 11, 2026 | Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mana... |
| CVE-2026-46703 | CRITICAL | 9.6 | 0.5% | Jun 10, 2026 | Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers ... |
| CVE-2026-46695 | CRITICAL | 10 | 0.3% | Jun 10, 2026 | Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers ... |
| CVE-2026-0274 | CRITICAL | 9.1 | 0.3% | Jun 10, 2026 | An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex X... |
| CVE-2026-50638 | CRITICAL | 9.1 | 0.3% | Jun 10, 2026 | Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections. The statsd p... |
| CVE-2026-50566 | CRITICAL | 9.9 | 0.3% | Jun 10, 2026 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic... |
| CVE-2026-50564 | CRITICAL | 9.9 | 0.3% | Jun 10, 2026 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic... |
| CVE-2026-50563 | CRITICAL | 9.9 | 0.3% | Jun 10, 2026 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic... |
| CVE-2026-50545 | CRITICAL | 9.9 | 0.3% | Jun 10, 2026 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic... |
| CVE-2026-46614 | CRITICAL | 9.8 | 0.4% | Jun 10, 2026 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic... |
| CVE-2026-20253 | CRITICAL | 9.8 | 88.2% | Jun 10, 2026 | In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or tr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now