2026 CVE Vulnerabilities
44,810 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49448 | CRITICAL | 9.8 | 0.4% | Jun 2, 2026 | authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can... |
| CVE-2026-42849 | CRITICAL | 9.3 | 0.4% | Jun 2, 2026 | authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of st... |
| CVE-2026-5076 | CRITICAL | 9.8 | 0.4% | Jun 2, 2026 | The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, a... |
| CVE-2026-38967 | CRITICAL | 9.8 | 0.3% | Jun 2, 2026 | CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values. |
| CVE-2026-42074 | CRITICAL | 9.8 | 0.5% | Jun 2, 2026 | OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0... |
| CVE-2026-0611 | CRITICAL | 9.8 | 0.7% | Jun 2, 2026 | Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code... |
| CVE-2026-47117 | CRITICAL | 9.8 | 0.9% | Jun 2, 2026 | OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The pr... |
| CVE-2026-7198 | CRITICAL | 9.8 | 0.4% | Jun 2, 2026 | CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unaut... |
| CVE-2026-10611 | CRITICAL | 10 | 0.4% | Jun 2, 2026 | An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In... |
| CVE-2026-42684 | CRITICAL | 9.3 | 0.3% | Jun 2, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Porta... |
| CVE-2026-34906 | CRITICAL | 9.3 | 0.6% | Jun 2, 2026 | Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to perform Remote Code Ex... |
| CVE-2026-8206 | CRITICAL | 9.8 | 1.3% | Jun 2, 2026 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalati... |
| CVE-2026-25879 | CRITICAL | 9.8 | 0.4% | Jun 1, 2026 | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent ex... |
| CVE-2026-40965 | CRITICAL | 10 | 0.3% | Jun 1, 2026 | Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vul... |
| CVE-2026-9319 | CRITICAL | 9 | 0.5% | Jun 1, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of... |
| CVE-2026-9311 | CRITICAL | 9 | 0.5% | Jun 1, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security co... |
| CVE-2026-8644 | CRITICAL | 9.1 | 0.3% | Jun 1, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing. |
| CVE-2026-49121 | CRITICAL | 9.8 | 1.1% | Jun 1, 2026 | AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the ... |
| CVE-2026-22872 | CRITICAL | 9.1 | 0.4% | Jun 1, 2026 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin pri... |
| CVE-2026-45132 | CRITICAL | 10 | 0.3% | Jun 1, 2026 | CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow ... |
| CVE-2026-45131 | CRITICAL | 10 | 0.3% | Jun 1, 2026 | CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow ... |
| CVE-2026-44211 | CRITICAL | 9.6 | 0.2% | Jun 1, 2026 | Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a... |
| CVE-2026-42672 | CRITICAL | 9.3 | 0.2% | Jun 1, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit W... |
| CVE-2026-8931 | CRITICAL | 9.4 | 0.7% | Jun 1, 2026 | A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3. |
| CVE-2026-48879 | CRITICAL | 9.8 | 0.3% | Jun 1, 2026 | Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now