2026 CVE Vulnerabilities
59,898 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-43663 | MEDIUM | 6.5 | 0.2% | Jun 29, 2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7... |
| CVE-2026-39872 | MEDIUM | 6.5 | 0.2% | Jun 29, 2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7... |
| CVE-2026-39868 | CRITICAL | 9.1 | 0.9% | Jun 29, 2026 | This issue was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5... |
| CVE-2026-37637 | CRITICAL | 9.1 | 0.5% | Jun 29, 2026 | An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php compon... |
| CVE-2026-31016 | MEDIUM | 6.5 | 0.2% | Jun 29, 2026 | Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 and before allows a remote attacker to escal... |
| CVE-2026-28979 | MEDIUM | 6.5 | 0.3% | Jun 29, 2026 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 18.... |
| CVE-2026-13763 | CRITICAL | 9.8 | 0.5% | Jun 29, 2026 | Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote ... |
| CVE-2026-13762 | CRITICAL | 9.8 | 0.5% | Jun 29, 2026 | Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to by... |
| CVE-2026-13593 | MEDIUM | 6.5 | 0.2% | Jun 29, 2026 | CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away. The minif... |
| CVE-2026-13008 | — | — | — | Jun 29, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-57700. Reason: This candidate is a ... |
| CVE-2026-58000 | HIGH | 8.8 | 1.4% | Jun 29, 2026 | luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKe... |
| CVE-2026-57999 | HIGH | 8.8 | 1.2% | Jun 29, 2026 | luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that allows... |
| CVE-2026-53428 | MEDIUM | 6.9 | — | Jun 29, 2026 | Memory Allocation with Excessive Size Value vulnerability in leandrocp mdex allows an unauthenticated attacker to cause ... |
| CVE-2026-53427 | LOW | 2.3 | — | Jun 29, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in leandrocp MDEx all... |
| CVE-2026-13757 | MEDIUM | 6.2 | 0.1% | Jun 29, 2026 | A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_mes... |
| CVE-2026-57960 | HIGH | 8.3 | 0.3% | Jun 29, 2026 | Hi.Events through 1.9.0 public check-in list endpoints use short_id as sole access control, allowing unauthenticated acc... |
| CVE-2026-57959 | HIGH | 8.2 | 0.2% | Jun 29, 2026 | Hi.Events through 1.9.0 contains a promo code validation vulnerability where reservation validates usage count before as... |
| CVE-2026-57958 | MEDIUM | 6.1 | — | Jun 29, 2026 | Mixpost through 2.6.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to e... |
| CVE-2026-57957 | MEDIUM | 4.7 | 0.3% | Jun 29, 2026 | Papermark through 0.22.0 contains a cross-origin resource sharing (CORS) misconfiguration vulnerability that allows unau... |
| CVE-2026-57956 | MEDIUM | 6.4 | 0.2% | Jun 29, 2026 | SigNoz before 0.133.0 contains a broken access control vulnerability that allows authenticated users to access other org... |
| CVE-2026-57955 | HIGH | 8.5 | 0.2% | Jun 29, 2026 | SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary C... |
| CVE-2026-57954 | MEDIUM | 5.3 | 0.2% | Jun 29, 2026 | Elide through 7.1.17 fails to enforce @ReadPermission on client-supplied sort expressions in SortingImpl.getValidSorting... |
| CVE-2026-57953 | MEDIUM | 5.4 | 0.2% | Jun 29, 2026 | Mythic before 3.4.0.60 contains an authorization bypass vulnerability that allows authenticated spectator-role users to ... |
| CVE-2026-57952 | MEDIUM | 6.5 | 0.2% | Jun 29, 2026 | Mythic before 3.4.0.60 contains an authorization bypass vulnerability in four REST endpoints (c2profile_config_check_web... |
| CVE-2026-57951 | HIGH | 7.1 | 0.2% | Jun 29, 2026 | Mythic before 3.4.0.60 contains a broken hasura permission filter on the payload_build_step table with an always-satisfi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now