2026 CVE Vulnerabilities
44,088 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53476 | CRITICAL | 9.6 | 0.3% | Jun 10, 2026 | A flaw was found in assisted-migration-agent. An unauthenticated attacker, located on the same local area network (LAN),... |
| CVE-2026-45558 | CRITICAL | 9.9 | 0.4% | Jun 10, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th... |
| CVE-2026-45556 | CRITICAL | 9.9 | 0.4% | Jun 10, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PO... |
| CVE-2026-45552 | CRITICAL | 9.9 | 0.3% | Jun 10, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th... |
| CVE-2026-45550 | CRITICAL | 9.1 | 0.2% | Jun 10, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, PU... |
| CVE-2026-9067 | CRITICAL | 9.1 | 0.4% | Jun 10, 2026 | The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend ... |
| CVE-2026-26241 | CRITICAL | 9.1 | 0.3% | Jun 10, 2026 | A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vu... |
| CVE-2026-26240 | CRITICAL | 9.1 | 0.3% | Jun 10, 2026 | A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vu... |
| CVE-2026-44963 | CRITICAL | 9.4 | 2.0% | Jun 9, 2026 | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. |
| CVE-2026-48303 | CRITICAL | 10 | 0.6% | Jun 9, 2026 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerabil... |
| CVE-2026-47938 | CRITICAL | 10 | 0.4% | Jun 9, 2026 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by a Server-Side Request Forgery (SSRF) ... |
| CVE-2026-47928 | CRITICAL | 9.6 | 8.3% | Jun 9, 2026 | ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could re... |
| CVE-2026-36727 | CRITICAL | 9.1 | 0.4% | Jun 9, 2026 | An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass... |
| CVE-2026-36721 | CRITICAL | 9.8 | 0.3% | Jun 9, 2026 | A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to ... |
| CVE-2026-30141 | CRITICAL | 9.8 | 0.6% | Jun 9, 2026 | An issue was discovered in bitbank2 AnimatedGIF v2.2.0. A buffer overflow in the DecodeLZW function allows remote attack... |
| CVE-2026-10045 | CRITICAL | 9.8 | 0.2% | Jun 9, 2026 | Shenzhen Kangda Xin Intelligent Network Technology Company's router, model DR300, version 2.1.2.121, contains hardcoded ... |
| CVE-2026-34691 | CRITICAL | 9.3 | 0.2% | Jun 9, 2026 | Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting ... |
| CVE-2026-49841 | CRITICAL | 9.8 | 0.4% | Jun 9, 2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ... |
| CVE-2026-49840 | CRITICAL | 9.1 | 0.3% | Jun 9, 2026 | FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to ... |
| CVE-2026-47643 | CRITICAL | 9.8 | 0.8% | Jun 9, 2026 | External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network... |
| CVE-2026-47291 | CRITICAL | 9.8 | 21.5% | Jun 9, 2026 | Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network. |
| CVE-2026-47281 | CRITICAL | 9.6 | 0.6% | Jun 9, 2026 | Missing authorization in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-45657 | CRITICAL | 9.8 | 15.5% | Jun 9, 2026 | Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network. |
| CVE-2026-45602 | CRITICAL | 9.1 | 0.4% | Jun 9, 2026 | No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network. |
| CVE-2026-44815 | CRITICAL | 9.8 | 1.1% | Jun 9, 2026 | Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now