2026 CVE Vulnerabilities
44,805 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11651 | CRITICAL | 9.6 | 0.3% | Jun 9, 2026 | Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code i... |
| CVE-2026-11638 | CRITICAL | 9.6 | 0.3% | Jun 9, 2026 | Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a s... |
| CVE-2026-11634 | CRITICAL | 9.6 | 0.3% | Jun 9, 2026 | Use after free in Gamepad in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker to potentially p... |
| CVE-2026-52778 | CRITICAL | 9.8 | 0.6% | Jun 8, 2026 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, an unsafe execution vulnerability exists in the Bazar f... |
| CVE-2026-11393 | CRITICAL | 9 | 0.3% | Jun 8, 2026 | Improper neutralization of triple-quote characters during Python code generation in AgentCore CLI before v0.14.2 might a... |
| CVE-2026-46289 | CRITICAL | 9.8 | 0.5% | Jun 8, 2026 | In the Linux kernel, the following vulnerability has been resolved: lib/scatterlist: fix length calculations in extract... |
| CVE-2026-41448 | CRITICAL | 9.4 | 0.5% | Jun 8, 2026 | AdGuard Home, when started with the --glinet flag, contains an authentication bypass vulnerability that allows unauthent... |
| CVE-2026-39910 | CRITICAL | 9.8 | 0.3% | Jun 8, 2026 | STACKIT IaaS API contains a missing authorization check vulnerability that allows authenticated, low-privileged attacker... |
| CVE-2026-25555 | CRITICAL | 9.8 | 1.5% | Jun 8, 2026 | OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middlewa... |
| CVE-2026-46442 | CRITICAL | 9.9 | 3.0% | Jun 8, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /a... |
| CVE-2026-46441 | CRITICAL | 9.6 | 0.3% | Jun 8, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass ... |
| CVE-2026-46440 | CRITICAL | 9.1 | 0.3% | Jun 8, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the che... |
| CVE-2026-44631 | CRITICAL | 9.8 | 0.5% | Jun 8, 2026 | Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue a... |
| CVE-2026-42861 | CRITICAL | 9.6 | 0.3% | Jun 8, 2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass ... |
| CVE-2026-42535 | CRITICAL | 9.1 | 0.5% | Jun 8, 2026 | A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate t... |
| CVE-2026-29167 | CRITICAL | 9.8 | 0.7% | Jun 8, 2026 | Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apac... |
| CVE-2026-50751 | CRITICAL | 9.3 | 82.6% | Jun 8, 2026 | A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows ... |
| CVE-2026-11499 | CRITICAL | 9.8 | 6.6% | Jun 8, 2026 | A vulnerability was determined in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formDOMAINBLK of th... |
| CVE-2026-11429 | CRITICAL | 10 | 1.1% | Jun 5, 2026 | Two endpoints in the Vault Service ScriptsController, shared by Altium Enterprise Server and Altium 365, accept file upl... |
| CVE-2026-11423 | CRITICAL | 9.4 | 0.3% | Jun 5, 2026 | A path traversal vulnerability exists in the Altium Enterprise Server Collaboration Service due to improper handling of ... |
| CVE-2026-45779 | CRITICAL | 9.8 | 0.5% | Jun 5, 2026 | OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL injection vulnerability exists in Open X... |
| CVE-2026-45777 | CRITICAL | 9.8 | 0.4% | Jun 5, 2026 | OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version ... |
| CVE-2026-45758 | CRITICAL | 9.6 | 0.3% | Jun 5, 2026 | Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, ... |
| CVE-2026-11420 | CRITICAL | 9.8 | 0.7% | Jun 5, 2026 | Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauth... |
| CVE-2026-11414 | CRITICAL | 9.8 | 0.5% | Jun 5, 2026 | A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Beca... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now