2026 CVE Vulnerabilities
44,115 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42904 | CRITICAL | 9.6 | 0.4% | Jun 9, 2026 | Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent netw... |
| CVE-2026-38615 | CRITICAL | 9.8 | 0.8% | Jun 9, 2026 | DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php. |
| CVE-2026-34182 | CRITICAL | 9.1 | 0.2% | Jun 9, 2026 | Issue Summary: Cryptographic Message Services (CMS) processing fails to perform sufficient input validation on the ciphe... |
| CVE-2026-26142 | CRITICAL | 9.8 | 1.9% | Jun 9, 2026 | Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network. |
| CVE-2026-8025 | CRITICAL | 9.8 | 0.3% | Jun 9, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in MOSK Information T... |
| CVE-2026-25089 | CRITICAL | 9.8 | 36.1% | Jun 9, 2026 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F... |
| CVE-2026-10523 | CRITICAL | 9.8 | 47.2% | Jun 9, 2026 | An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allow... |
| CVE-2026-10520 | CRITICAL | 10 | 99.0% | Jun 9, 2026 | An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote ... |
| CVE-2026-7486 | CRITICAL | 9.8 | 0.3% | Jun 9, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Software In... |
| CVE-2026-46325 | CRITICAL | 9.8 | 0.3% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to-va conversion for MR page siz... |
| CVE-2026-46316 | CRITICAL | 9.3 | 0.4% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache re... |
| CVE-2026-46749 | CRITICAL | 9.8 | 0.1% | Jun 9, 2026 | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a pas... |
| CVE-2026-41031 | CRITICAL | 9.3 | 0.2% | Jun 9, 2026 | A Stored Cross-Site Scripting vulnerability in Vinna Process Monitor Version 4.0 Service Pack 1 (Build 63255) allows an ... |
| CVE-2026-10731 | CRITICAL | 9.3 | 0.3% | Jun 9, 2026 | SQL injection in the ‘two_steps_auth_code’ parameter processed by the ‘twoStepsAuthVerification’ function within the ‘/u... |
| CVE-2026-9698 | CRITICAL | 9.8 | 0.5% | Jun 9, 2026 | DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when Raise... |
| CVE-2026-44083 | CRITICAL | 9.8 | 0.5% | Jun 9, 2026 | An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attack... |
| CVE-2026-5067 | CRITICAL | 9.8 | 0.6% | Jun 9, 2026 | A remote, unauthenticated attacker can trigger memory corruption in Zephyr's HTTP server WebSocket upgrade path by sendi... |
| CVE-2026-41855 | CRITICAL | 9.8 | 0.3% | Jun 9, 2026 | In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.sprin... |
| CVE-2026-44748 | CRITICAL | 9.9 | 0.2% | Jun 9, 2026 | SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtai... |
| CVE-2026-40128 | CRITICAL | 9 | 0.5% | Jun 9, 2026 | SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon... |
| CVE-2026-27671 | CRITICAL | 9.8 | 0.4% | Jun 9, 2026 | Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP ... |
| CVE-2026-11697 | CRITICAL | 9.6 | 0.2% | Jun 9, 2026 | Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to p... |
| CVE-2026-11671 | CRITICAL | 9.6 | 0.2% | Jun 9, 2026 | Use after free in Navigation in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a... |
| CVE-2026-11659 | CRITICAL | 9.6 | 0.3% | Jun 9, 2026 | Integer overflow in UI in Google Chrome on Linux prior to 149.0.7827.103 allowed a remote attacker to potentially perfor... |
| CVE-2026-11654 | CRITICAL | 9.6 | 0.3% | Jun 9, 2026 | Use after free in CameraCapture in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now