2026 CVE Vulnerabilities
60,112 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-50765 | MEDIUM | 6.1 | 0.2% | Jun 26, 2026 | A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Man... |
| CVE-2026-49984 | HIGH | 7.7 | 0.4% | Jun 26, 2026 | Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage ba... |
| CVE-2026-49869 | CRITICAL | 10 | 1.0% | Jun 26, 2026 | Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestr... |
| CVE-2026-45807 | HIGH | 7.7 | 0.4% | Jun 26, 2026 | Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.43 and 1.3.19, several Kestra API endpoints ... |
| CVE-2026-38571 | MEDIUM | 4.6 | 0.2% | Jun 26, 2026 | Cleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands, ... |
| CVE-2026-36908 | MEDIUM | 5.5 | 0.2% | Jun 26, 2026 | A stack overflow in the AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity component of axiomatic-systems Bento4 before v1.8... |
| CVE-2026-36907 | MEDIUM | 5.5 | 0.2% | Jun 26, 2026 | A stack overflow in the AP4_StsdAtom::AP4_StsdAtom component of axiomatic-systems Bento4 before v1.8.9allows attackers t... |
| CVE-2026-36478 | HIGH | 7.5 | 0.4% | Jun 26, 2026 | An issue in Technitium DNS Server v.14.3 and before allows a remote attacker to cause a denial of service via the DnsSer... |
| CVE-2026-54353 | HIGH | 7.1 | 0.2% | Jun 26, 2026 | Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypas... |
| CVE-2026-54352 | CRITICAL | 9.6 | 0.5% | Jun 26, 2026 | Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/ro... |
| CVE-2026-54351 | CRITICAL | 9.6 | 0.4% | Jun 26, 2026 | Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly acce... |
| CVE-2026-54350 | CRITICAL | 9.8 | 0.4% | Jun 26, 2026 | Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase ap... |
| CVE-2026-52885 | MEDIUM | 6.3 | 0.2% | Jun 26, 2026 | Notepad++ is a free and open-source source code editor. Prior to 8.9.6.4, NppCommands.cpp checks the HMAC of the on-disk... |
| CVE-2026-52884 | HIGH | 7.8 | 0.1% | Jun 26, 2026 | Notepad++ is a free and open-source source code editor. In v8.9.6.1, isInTrustedDirectory() does NOT canonicalize the pa... |
| CVE-2026-50137 | CRITICAL | 9.4 | 0.3% | Jun 26, 2026 | Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or can enumerate a worksp... |
| CVE-2026-50136 | MEDIUM | 5.3 | 0.3% | Jun 26, 2026 | Budibase is an open-source low-code platform. Prior to 3.39.3, the application server exposes an unauthenticated endpoin... |
| CVE-2026-50132 | HIGH | 7.3 | 0.2% | Jun 26, 2026 | Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a publi... |
| CVE-2026-48800 | HIGH | 7.8 | 0.4% | Jun 26, 2026 | Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <Command> tag text content inside <UserDef... |
| CVE-2026-48778 | HIGH | 7.8 | 1.4% | Jun 26, 2026 | Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <GUIConfig name="commandLineInterpreter"> ... |
| CVE-2026-48770 | MEDIUM | 5 | 0.3% | Jun 26, 2026 | Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, a local process in the same interactive Window... |
| CVE-2026-46710 | HIGH | 7.8 | 0.1% | Jun 26, 2026 | Notepad++ is a free and open-source source code editor. From 8.9.4 until 8.9.6, Notepad++ contains a local privilege esc... |
| CVE-2026-46604 | HIGH | 7.5 | 0.3% | Jun 26, 2026 | The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. |
| CVE-2026-39031 | MEDIUM | 5.5 | 0.1% | Jun 26, 2026 | Lansweeper lsrunase 2.0 and lsencrypt 2.0 use RC4 encryption with a hardcoded 142-byte static key array to encrypt crede... |
| CVE-2026-38641 | HIGH | 7.5 | 0.2% | Jun 26, 2026 | An issue in the DSO::mmap_and_copy function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) ... |
| CVE-2026-38639 | HIGH | 7.5 | 0.2% | Jun 26, 2026 | An issue in the parse_month function (/time/strptime.rs) of relibc commit ab6a2e allows attackers to cause a Denial of S... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now