2026 CVE Vulnerabilities
60,149 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30041 | HIGH | 7.5 | — | Jun 26, 2026 | An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code... |
| CVE-2026-30040 | MEDIUM | 6.5 | — | Jun 26, 2026 | A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 allows attackers to cause a execute arbitrary... |
| CVE-2026-24547 | MEDIUM | 5.3 | — | Jun 26, 2026 | Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions. |
| CVE-2026-57940 | LOW | 2.1 | — | Jun 26, 2026 | HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The functi... |
| CVE-2026-57926 | CRITICAL | 9.8 | 0.4% | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack |
| CVE-2026-57925 | MEDIUM | 5.3 | 0.2% | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags |
| CVE-2026-57924 | MEDIUM | 5.3 | 0.2% | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details |
| CVE-2026-57923 | HIGH | 7.5 | 0.2% | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying pr... |
| CVE-2026-57922 | MEDIUM | 5.3 | 0.1% | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible |
| CVE-2026-57921 | HIGH | 7.5 | 0.2% | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment te... |
| CVE-2026-53914 | CRITICAL | 9.8 | 0.1% | Jun 26, 2026 | In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata |
| CVE-2026-13426 | MEDIUM | 5.4 | — | Jun 26, 2026 | The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path paramet... |
| CVE-2026-57920 | HIGH | 7.7 | 0.2% | Jun 26, 2026 | Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certai... |
| CVE-2026-57915 | HIGH | 7.3 | 0.3% | Jun 26, 2026 | It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized... |
| CVE-2026-40711 | HIGH | 8 | — | Jun 26, 2026 | Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-po... |
| CVE-2026-57914 | MEDIUM | 6.5 | — | Jun 26, 2026 | By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow ... |
| CVE-2026-57620 | MEDIUM | 6.5 | — | Jun 26, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclu... |
| CVE-2026-57918 | HIGH | 7.1 | — | Jun 26, 2026 | libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c d... |
| CVE-2026-57913 | HIGH | 7.5 | — | Jun 26, 2026 | Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transc... |
| CVE-2026-57912 | HIGH | 7.5 | — | Jun 26, 2026 | Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited students, and notes e... |
| CVE-2026-57473 | MEDIUM | 5.8 | — | Jun 26, 2026 | A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911)... |
| CVE-2026-13325 | — | — | 0.2% | Jun 26, 2026 | Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed. |
| CVE-2026-6658 | MEDIUM | 5.4 | 0.2% | Jun 26, 2026 | A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows for Cross-site Scripting (XSS) via unsanitized `text/vnd.... |
| CVE-2026-1869 | MEDIUM | 6.5 | 0.2% | Jun 26, 2026 | The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom U... |
| CVE-2026-11702 | HIGH | 7.5 | 0.3% | Jun 26, 2026 | Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes. When an objec... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now