2026 CVE Vulnerabilities
44,807 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11414 | CRITICAL | 9.8 | 0.5% | Jun 5, 2026 | A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Beca... |
| CVE-2026-46496 | CRITICAL | 9.3 | 0.2% | Jun 5, 2026 | HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability e... |
| CVE-2026-46399 | CRITICAL | 9.4 | 0.3% | Jun 5, 2026 | HAX CMS helps manage microsite universe with PHP or NodeJs backends. The PHP version of HAX CMS prior to version 26.0.0 ... |
| CVE-2026-46396 | CRITICAL | 9.3 | 0.2% | Jun 5, 2026 | HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability e... |
| CVE-2026-46395 | CRITICAL | 9.3 | 0.3% | Jun 5, 2026 | HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the `hmacBase64()` functio... |
| CVE-2026-46389 | CRITICAL | 9.8 | 0.3% | Jun 5, 2026 | UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by UDS Co... |
| CVE-2026-10580 | CRITICAL | 9.8 | 2.8% | Jun 5, 2026 | The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrat... |
| CVE-2026-45750 | CRITICAL | 9 | 0.3% | Jun 5, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v... |
| CVE-2026-45748 | CRITICAL | 9.8 | 1.7% | Jun 5, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST ... |
| CVE-2026-45746 | CRITICAL | 9 | 0.4% | Jun 5, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v... |
| CVE-2026-45744 | CRITICAL | 9.9 | 2.0% | Jun 5, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to v... |
| CVE-2026-36500 | CRITICAL | 9.1 | 0.7% | Jun 5, 2026 | An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory t... |
| CVE-2026-9270 | CRITICAL | 9.1 | 0.3% | Jun 5, 2026 | DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does not properly sanitis... |
| CVE-2026-11362 | CRITICAL | 9.8 | 0.4% | Jun 5, 2026 | DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. DataDog::DogStatsd does not ... |
| CVE-2026-10879 | CRITICAL | 9.8 | 0.4% | Jun 5, 2026 | DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The pr... |
| CVE-2026-6274 | CRITICAL | 9.8 | 0.5% | Jun 5, 2026 | Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electron... |
| CVE-2026-49777 | CRITICAL | 10 | 1.7% | Jun 5, 2026 | Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce... |
| CVE-2026-48907 | CRITICAL | 9.8 | 80.4% | Jun 5, 2026 | A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated us... |
| CVE-2026-7763 | CRITICAL | 9.8 | 0.5% | Jun 5, 2026 | A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software... |
| CVE-2026-7762 | CRITICAL | 9.8 | 0.6% | Jun 5, 2026 | A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 softwa... |
| CVE-2026-11293 | CRITICAL | 9.6 | 0.2% | Jun 5, 2026 | Use after free in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandb... |
| CVE-2026-11282 | CRITICAL | 9.6 | 0.2% | Jun 5, 2026 | Insufficient policy enforcement in Sandbox in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to... |
| CVE-2026-11250 | CRITICAL | 9.6 | 0.2% | Jun 5, 2026 | Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compr... |
| CVE-2026-48567 | CRITICAL | 9.8 | 1.0% | Jun 4, 2026 | Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a networ... |
| CVE-2026-11213 | CRITICAL | 9.6 | 0.2% | Jun 4, 2026 | Insufficient validation of untrusted input in Reading Mode in Google Chrome prior to 149.0.7827.53 allowed a remote atta... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now