2026 CVE Vulnerabilities
60,149 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11625 | HIGH | 7.5 | 0.3% | Jun 26, 2026 | Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. When an object is in... |
| CVE-2026-57881 | CRITICAL | 9.8 | 0.4% | Jun 26, 2026 | An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.1... |
| CVE-2026-57880 | CRITICAL | 9.8 | 0.5% | Jun 26, 2026 | An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12... |
| CVE-2026-57879 | CRITICAL | 9.8 | 0.5% | Jun 26, 2026 | An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12... |
| CVE-2026-57878 | CRITICAL | 9.8 | 0.5% | Jun 26, 2026 | An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.... |
| CVE-2026-57877 | HIGH | 8.6 | 0.2% | Jun 26, 2026 | An unauthenticated format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier.... |
| CVE-2026-57876 | HIGH | 7.5 | 0.3% | Jun 26, 2026 | An unauthenticated out-of-bounds write vulnerability exists in onvif.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 an... |
| CVE-2026-57875 | HIGH | 7.5 | 1.3% | Jun 26, 2026 | An unauthenticated NULL pointer dereference vulnerability exists in the HTTP request parsing logic of multiple CGI compo... |
| CVE-2026-57874 | HIGH | 7.5 | 0.3% | Jun 26, 2026 | An unauthenticated buffer overflow vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V... |
| CVE-2026-57873 | HIGH | 7.5 | 0.2% | Jun 26, 2026 | An unauthenticated NULL pointer dereference vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-... |
| CVE-2026-57872 | HIGH | 7.5 | 1.0% | Jun 26, 2026 | An unauthenticated directory traversal vulnerability exists in get_fcont.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.1... |
| CVE-2026-49486 | HIGH | 7.5 | 0.4% | Jun 26, 2026 | The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p(... |
| CVE-2026-2053 | CRITICAL | 10 | 0.2% | Jun 26, 2026 | The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or ... |
| CVE-2026-8380 | MEDIUM | 6.5 | 0.2% | Jun 26, 2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post... |
| CVE-2026-10835 | HIGH | 7.7 | 0.2% | Jun 26, 2026 | The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter passed to one ... |
| CVE-2026-10823 | HIGH | 7.5 | 0.1% | Jun 26, 2026 | The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST API endpoints and do... |
| CVE-2026-8797 | HIGH | 8.5 | 0.1% | Jun 26, 2026 | An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access t... |
| CVE-2026-8661 | MEDIUM | 4.8 | 0.3% | Jun 26, 2026 | Server-Side Request Forgery in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin on Linux in versions ... |
| CVE-2026-50745 | MEDIUM | 6.1 | 0.1% | Jun 26, 2026 | A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script w... |
| CVE-2026-50744 | MEDIUM | 4.3 | 0.2% | Jun 26, 2026 | A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login me... |
| CVE-2026-50742 | MEDIUM | 5.4 | 0.1% | Jun 26, 2026 | A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revi... |
| CVE-2026-50741 | HIGH | 8.8 | 0.3% | Jun 26, 2026 | Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix ... |
| CVE-2026-50740 | MEDIUM | 5.4 | 0.2% | Jun 26, 2026 | A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and ea... |
| CVE-2026-50739 | MEDIUM | 4.3 | 0.2% | Jun 26, 2026 | A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation o... |
| CVE-2026-48936 | LOW | 3.3 | 0.1% | Jun 26, 2026 | A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now