2026 CVE Vulnerabilities
60,149 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48935 | LOW | 3.3 | 0.1% | Jun 26, 2026 | A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with ... |
| CVE-2026-48934 | MEDIUM | 4.3 | 0.3% | Jun 26, 2026 | A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability ... |
| CVE-2026-48933 | HIGH | 7.5 | 3.7% | Jun 26, 2026 | A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2Gi... |
| CVE-2026-48930 | CRITICAL | 9.8 | 0.3% | Jun 26, 2026 | A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c... |
| CVE-2026-48928 | MEDIUM | 5.4 | 0.2% | Jun 26, 2026 | A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulne... |
| CVE-2026-48619 | HIGH | 7.5 | 0.5% | Jun 26, 2026 | A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out... |
| CVE-2026-48618 | MEDIUM | 6.5 | 3.2% | Jun 26, 2026 | A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth ... |
| CVE-2026-48615 | HIGH | 7.5 | 0.4% | Jun 26, 2026 | A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. Wh... |
| CVE-2026-13226 | MEDIUM | 6.5 | 0.3% | Jun 26, 2026 | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection ... |
| CVE-2026-9222 | CRITICAL | 9.2 | 0.2% | Jun 26, 2026 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authe... |
| CVE-2026-9221 | HIGH | 8.7 | 0.2% | Jun 26, 2026 | The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request si... |
| CVE-2026-9220 | HIGH | 8.7 | 0.2% | Jun 26, 2026 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and i... |
| CVE-2026-9219 | HIGH | 8.3 | 0.2% | Jun 26, 2026 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derive... |
| CVE-2026-43920 | MEDIUM | 6.9 | 0.5% | Jun 26, 2026 | FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patch... |
| CVE-2026-13322 | LOW | 3.8 | 0.1% | Jun 26, 2026 | A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Re... |
| CVE-2026-13318 | MEDIUM | 6.4 | 0.2% | Jun 26, 2026 | A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processing a port-... |
| CVE-2026-13218 | MEDIUM | 4.2 | 0.1% | Jun 26, 2026 | A flaw was found in KubeVirt's virt-handler network cache handling. The WriteToCachedFile function writes data to a laun... |
| CVE-2026-13083 | MEDIUM | 6.9 | 0.2% | Jun 26, 2026 | A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper es... |
| CVE-2026-12993 | MEDIUM | 6.5 | 0.4% | Jun 26, 2026 | A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but d... |
| CVE-2026-40941 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import sign... |
| CVE-2026-40084 | MEDIUM | 6.5 | 0.3% | Jun 25, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Tra... |
| CVE-2026-40083 | HIGH | 7.2 | 0.3% | Jun 25, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have SQL Injection through... |
| CVE-2026-40082 | MEDIUM | 5.4 | 0.2% | Jun 25, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have missing session_regen... |
| CVE-2026-40080 | MEDIUM | 6.1 | 0.1% | Jun 25, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Open Red... |
| CVE-2026-8720 | HIGH | 7.5 | 0.1% | Jun 25, 2026 | wc_Blake2bHmacFinal and wc_Blake2sHmacFinal discard the message when the key length exceeds the block size, producing a ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now