2026 CVE Vulnerabilities
44,809 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-36182 | CRITICAL | 9.8 | 0.2% | Jun 4, 2026 | GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, possibly allowing atta... |
| CVE-2026-10868 | CRITICAL | 9 | 0.2% | Jun 4, 2026 | A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplie... |
| CVE-2026-35906 | CRITICAL | 9.6 | 0.5% | Jun 4, 2026 | An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthenticated at... |
| CVE-2026-35905 | CRITICAL | 9.8 | 0.4% | Jun 4, 2026 | T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to contain a hardcoded passw... |
| CVE-2026-35904 | CRITICAL | 9.8 | 0.5% | Jun 4, 2026 | Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, an... |
| CVE-2026-8037 | CRITICAL | 9.8 | 99.3% | Jun 4, 2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated atta... |
| CVE-2026-4104 | CRITICAL | 9.8 | 0.3% | Jun 4, 2026 | Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and ... |
| CVE-2026-50225 | CRITICAL | 9.1 | 0.2% | Jun 4, 2026 | The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems t... |
| CVE-2026-50214 | CRITICAL | 9.8 | 0.2% | Jun 4, 2026 | The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary... |
| CVE-2026-50211 | CRITICAL | 9.8 | 0.3% | Jun 4, 2026 | Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious... |
| CVE-2026-50208 | CRITICAL | 9.4 | 0.1% | Jun 4, 2026 | High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric enc... |
| CVE-2026-49191 | CRITICAL | 9.8 | 0.3% | Jun 4, 2026 | The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose... |
| CVE-2026-49188 | CRITICAL | 9.8 | 0.3% | Jun 4, 2026 | The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for u... |
| CVE-2026-49186 | CRITICAL | 9.8 | 0.3% | Jun 4, 2026 | The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe usin... |
| CVE-2026-49185 | CRITICAL | 9.8 | 0.4% | Jun 4, 2026 | The FieldX MDM adb messaging topic passes unverified payloads directly into Runtime.exec(), allowing command/instruction... |
| CVE-2026-41283 | CRITICAL | 9.9 | 0.7% | Jun 4, 2026 | OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints tha... |
| CVE-2026-46266 | CRITICAL | 9.1 | 0.3% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets using IPPROTO_RAW MUST drop incom... |
| CVE-2026-46244 | CRITICAL | 9.1 | 0.3% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_inner: Fix IPv6 inner_thoff desync ... |
| CVE-2026-36748 | CRITICAL | 9 | 0.3% | Jun 3, 2026 | RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile. |
| CVE-2026-36576 | CRITICAL | 9.8 | 1.5% | Jun 3, 2026 | An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 al... |
| CVE-2026-5241 | CRITICAL | 9.6 | 0.5% | Jun 3, 2026 | A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-control... |
| CVE-2026-35075 | CRITICAL | 9.8 | 0.5% | Jun 3, 2026 | An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full a... |
| CVE-2026-47065 | CRITICAL | 9.8 | 0.5% | Jun 3, 2026 | ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Ful... |
| CVE-2026-35482 | CRITICAL | 9.1 | 0.2% | Jun 2, 2026 | alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to versio... |
| CVE-2026-32625 | CRITICAL | 9.6 | 2.9% | Jun 2, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the M... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now