2026 CVE Vulnerabilities
59,915 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56124 | HIGH | 8.7 | 0.4% | Jun 29, 2026 | phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers t... |
| CVE-2026-55844 | HIGH | 7.5 | 0.2% | Jun 29, 2026 | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The... |
| CVE-2026-55607 | HIGH | 8.8 | 0.7% | Jun 29, 2026 | Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of w... |
| CVE-2026-49049 | HIGH | 7.5 | 0.2% | Jun 29, 2026 | The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary fil... |
| CVE-2026-46406 | MEDIUM | 6.1 | 0.2% | Jun 29, 2026 | Claude Code is an agentic coding tool. From 2.1.59 until 2.1.128, the Claude Code /copy command wrote responses to a ha... |
| CVE-2026-13579 | MEDIUM | 6.3 | — | Jun 29, 2026 | A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this issue is some unknown fu... |
| CVE-2026-13578 | MEDIUM | 6.3 | — | Jun 29, 2026 | A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an... |
| CVE-2026-13574 | LOW | 3.3 | 0.1% | Jun 29, 2026 | A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr i... |
| CVE-2026-13573 | LOW | 3.3 | 0.1% | Jun 29, 2026 | A vulnerability was found in llvm llvm-project up to 22.1.6. This affects the function llvm::StringMap::insert in the li... |
| CVE-2026-13572 | MEDIUM | 6.3 | 0.2% | Jun 29, 2026 | A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown functi... |
| CVE-2026-13571 | MEDIUM | 5.5 | — | Jun 29, 2026 | A flaw has been found in SourceCodester Simple Food Ordering System 1.0. The affected element is an unknown function of ... |
| CVE-2026-56457 | MEDIUM | 4.3 | 0.2% | Jun 29, 2026 | HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This... |
| CVE-2026-54371 | HIGH | 7.1 | 0.1% | Jun 29, 2026 | attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows ... |
| CVE-2026-54370 | HIGH | 7.2 | — | Jun 29, 2026 | acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local... |
| CVE-2026-54369 | HIGH | 7.1 | 0.2% | Jun 29, 2026 | acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(... |
| CVE-2026-40524 | HIGH | 8.1 | 0.3% | Jun 29, 2026 | FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the get_gl_transactions() function where the fil... |
| CVE-2026-40523 | HIGH | 8.1 | — | Jun 29, 2026 | FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Audit Trail report handler that allows authe... |
| CVE-2026-40522 | HIGH | 7.1 | — | Jun 29, 2026 | FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Bank Statement report handler that allows au... |
| CVE-2026-40521 | HIGH | 8.8 | 0.6% | Jun 29, 2026 | FrontAccounting before 2.4.20 contains a path traversal vulnerability in the attachment upload handler that allows authe... |
| CVE-2026-13676 | HIGH | 7.5 | 0.4% | Jun 29, 2026 | fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The I... |
| CVE-2026-13570 | LOW | 3.5 | — | Jun 29, 2026 | A vulnerability was detected in SourceCodester Inventory Management System 1.0. Impacted is an unknown function of the f... |
| CVE-2026-13569 | MEDIUM | 4.7 | — | Jun 29, 2026 | A security vulnerability has been detected in weng-xianhu EyouCMS up to 1.7.1. This issue affects some unknown processin... |
| CVE-2026-13568 | HIGH | 7.3 | 0.3% | Jun 29, 2026 | A weakness has been identified in SourceCodester Inventory Management System 1.0. This vulnerability affects unknown cod... |
| CVE-2026-13567 | MEDIUM | 4.3 | — | Jun 29, 2026 | A security flaw has been discovered in code-projects Online Music Site 1.0. This affects an unknown part of the file /Fr... |
| CVE-2026-13566 | HIGH | 7.3 | 0.3% | Jun 29, 2026 | A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now