2026 CVE Vulnerabilities
59,849 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-58012 | HIGH | 8.2 | 0.5% | Jun 30, 2026 | A flaw was found in GLib. A buffer over-read can occur in the g_regex_replace function when used with the `G_REGEX_RAW` ... |
| CVE-2026-58011 | HIGH | 7.5 | 0.5% | Jun 30, 2026 | A flaw was found in GLib. An out-of-bounds read of only 2 bytes can occur in the g_date_time_get_ymd function in the gli... |
| CVE-2026-58010 | HIGH | 8.2 | 0.5% | Jun 30, 2026 | A flaw was found in GLib. An off-by-one error can occur in the gvs_tuple_is_normal function in the glib/gvariant-seriali... |
| CVE-2026-53433 | HIGH | 7.5 | 0.1% | Jun 30, 2026 | fzf is vulnerable to a Denial of Service (DoS) due to inefficient HTTP body processing in the --listen mode due to ineff... |
| CVE-2026-53432 | HIGH | 7.5 | 0.1% | Jun 30, 2026 | fzf is vulnerable to Integer Overflow leading to crash in FuzzyMatchV2 function. When input line length is approximately... |
| CVE-2026-4629 | MEDIUM | 6.5 | 0.3% | Jun 30, 2026 | A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability b... |
| CVE-2026-47105 | — | — | — | Jun 30, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-44946 | HIGH | 7.4 | 0.3% | Jun 30, 2026 | A SAML authentication replay vulnerability in Rancher's Assertion Consumer Service (ACS) handler did not enforce one-t... |
| CVE-2026-14209 | MEDIUM | 4.3 | 0.2% | Jun 30, 2026 | A vulnerability was discovered in Keycloak's Admin UI extension that allows certain administrative users to bypass secur... |
| CVE-2026-13474 | HIGH | 7.5 | 0.4% | Jun 30, 2026 | Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Prof... |
| CVE-2026-12388 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user informati... |
| CVE-2026-10817 | HIGH | 7.5 | 0.4% | Jun 30, 2026 | Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is ... |
| CVE-2026-10816 | HIGH | 7.5 | 0.2% | Jun 30, 2026 | Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management I... |
| CVE-2026-8402 | CRITICAL | 9.8 | — | Jun 30, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electroni... |
| CVE-2026-57082 | MEDIUM | 5.9 | 0.2% | Jun 30, 2026 | Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG... |
| CVE-2026-57081 | HIGH | 7.5 | 0.3% | Jun 30, 2026 | Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via deeply nested bencoded input. bdecod... |
| CVE-2026-57080 | HIGH | 7.5 | 0.3% | Jun 30, 2026 | Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length ... |
| CVE-2026-57079 | MEDIUM | 5.3 | 0.3% | Jun 30, 2026 | Net::BitTorrent versions before 2.1.0 for Perl write files outside the download directory via path traversal in peer-sup... |
| CVE-2026-53692 | MEDIUM | 5.9 | — | Jun 30, 2026 | Redeight CMS version 1.0 uses the MD5 algorithm without a salt to store user passwords. Because MD5 is a cryptographical... |
| CVE-2026-53691 | HIGH | 8.6 | — | Jun 30, 2026 | An Unrestricted File Upload vulnerability in Redeight CMS version 1.0 allows authenticated attackers to achieve Remote C... |
| CVE-2026-53690 | CRITICAL | 9.3 | — | Jun 30, 2026 | An SQL Injection vulnerability exists in Redeight CMS version 1.0 via the "userEmail" parameter in the POST "/admin/inde... |
| CVE-2026-41053 | HIGH | 8.8 | 0.4% | Jun 30, 2026 | Incorrect authentication caching in the team member ship expansion of the Rancher Github authentication provider caused ... |
| CVE-2026-14162 | CRITICAL | 9.8 | — | Jun 30, 2026 | Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated... |
| CVE-2026-14161 | HIGH | 8.7 | — | Jun 30, 2026 | Hospital Quening Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated... |
| CVE-2026-13766 | CRITICAL | 9.8 | — | Jun 30, 2026 | DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers. The default SQL buil... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now