2026 CVE Vulnerabilities
59,898 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57950 | HIGH | 8.6 | 0.3% | Jun 29, 2026 | ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control vulnerability in ErpSaleOrderCon... |
| CVE-2026-57949 | HIGH | 7.1 | 0.2% | Jun 29, 2026 | ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module... |
| CVE-2026-57948 | HIGH | 7.6 | 0.1% | Jun 29, 2026 | Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the... |
| CVE-2026-57947 | HIGH | 8.5 | 0.2% | Jun 29, 2026 | Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that al... |
| CVE-2026-57946 | MEDIUM | 6.3 | 0.3% | Jun 29, 2026 | Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attacke... |
| CVE-2026-57945 | MEDIUM | 5.3 | 0.2% | Jun 29, 2026 | PhotoPrism before 260601-a7d098548 contains a broken access control vulnerability that allows authenticated non-admin us... |
| CVE-2026-57943 | MEDIUM | 6 | 0.2% | Jun 29, 2026 | LibrePhotos before 1.0.0 contains a broken object level authorization vulnerability in the SetPhotosShared endpoint that... |
| CVE-2026-57942 | MEDIUM | 6.9 | — | Jun 29, 2026 | LibreTranslate through 1.9.7, fixed in commit 397fd22, contains an IP spoofing vulnerability in the get_remote_address()... |
| CVE-2026-56783 | HIGH | 7.1 | 0.3% | Jun 29, 2026 | Parseable before 2.9.2 contains an information disclosure vulnerability in the notification-target API endpoints that re... |
| CVE-2026-56782 | CRITICAL | 9.8 | 3.0% | Jun 29, 2026 | Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that all... |
| CVE-2026-56781 | MEDIUM | 6.9 | 0.2% | Jun 29, 2026 | Teable before 2026-06-15T04-43-24Z.1912 contains an improper access control vulnerability that allows anonymous attacker... |
| CVE-2026-56780 | HIGH | 7.7 | 0.3% | Jun 29, 2026 | Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/passwor... |
| CVE-2026-56285 | HIGH | 8.6 | 0.4% | Jun 29, 2026 | Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded defaul... |
| CVE-2026-36848 | HIGH | 7.5 | 0.7% | Jun 29, 2026 | Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem. |
| CVE-2026-13592 | HIGH | 7.3 | 0.4% | Jun 29, 2026 | A vulnerability was detected in liftoff-sr CIPster up to e8e9dba09bf56962807d3504b783ccdb6287f3e4. Affected by this issu... |
| CVE-2026-11720 | CRITICAL | 9.1 | 0.4% | Jun 29, 2026 | A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstr... |
| CVE-2026-13752 | HIGH | 8 | 0.1% | Jun 29, 2026 | Improper neutralization of parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. An attac... |
| CVE-2026-13751 | CRITICAL | 9.6 | 0.1% | Jun 29, 2026 | Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request for... |
| CVE-2026-13591 | MEDIUM | 5 | — | Jun 29, 2026 | A weakness has been identified in DeepMyst Mysti 0.4.0. Affected is the function _isTrackedConversation of the file src/... |
| CVE-2026-13590 | MEDIUM | 5.6 | 0.4% | Jun 29, 2026 | A security flaw has been discovered in seladb PcapPlusPlus 25.05. This impacts the function pcpp::ModbusLayer::getLength... |
| CVE-2026-13589 | MEDIUM | 5.6 | — | Jun 29, 2026 | A vulnerability was identified in seladb PcapPlusPlus 25.05. This affects the function pcpp::TelnetLayer::getSubCommand ... |
| CVE-2026-13588 | MEDIUM | 5.6 | — | Jun 29, 2026 | A vulnerability was determined in seladb PcapPlusPlus 25.05. The impacted element is the function pcpp::SSLClientHelloMe... |
| CVE-2026-12912 | HIGH | 7.3 | 0.4% | Jun 29, 2026 | A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLo... |
| CVE-2026-12672 | — | — | — | Jun 29, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2026-9105 | MEDIUM | 6.5 | 0.3% | Jun 29, 2026 | An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now