2026 CVE Vulnerabilities
60,149 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57700 | CRITICAL | 10 | 0.4% | Jun 25, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This i... |
| CVE-2026-56790 | HIGH | 7.3 | 0.2% | Jun 25, 2026 | CANBoat through 6.22, fixed in commit a5a22b7, contains an off-by-one global buffer overflow in the searchForPgn() funct... |
| CVE-2026-56789 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | RTKLIB through 2.4.3 contains a heap buffer overflow vulnerability in the readrnxobsb function in src/rinex.c that allow... |
| CVE-2026-56788 | HIGH | 7.1 | 0.1% | Jun 25, 2026 | RTKLIB through 2.4.3 contains an out-of-bounds read vulnerability in getcodepri function when processing unrecognized RI... |
| CVE-2026-56787 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | RTKLIB through 2.4.3 contains an off-by-one out-of-bounds read vulnerability in the decode_ssr3 function at src/rtcm3.c:... |
| CVE-2026-56786 | CRITICAL | 9.8 | 0.4% | Jun 25, 2026 | RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function that fails to clamp lengt... |
| CVE-2026-56779 | MEDIUM | 6.4 | 0.2% | Jun 25, 2026 | MaxKB before 2.10.0 contains a server-side request forgery vulnerability in tool creation and update endpoints that allo... |
| CVE-2026-56774 | MEDIUM | 5.4 | 0.3% | Jun 25, 2026 | Kanboard through 1.2.52, fixed in commit 928c68a, UserViewController::removeSession fails to validate the session id par... |
| CVE-2026-56772 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | NewsBlur before 14.5.0 contains a broken access control vulnerability that allows authenticated users to read private no... |
| CVE-2026-56771 | HIGH | 8.5 | 0.2% | Jun 25, 2026 | NewsBlur before version 14.5.0 contains a server-side request forgery vulnerability in the add_url endpoint that allows ... |
| CVE-2026-56770 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | libais through 0.15 VdmStream::AddLine uses an unchecked sentinel value as a vector index when processing AIS sentences ... |
| CVE-2026-56769 | HIGH | 8.5 | 0.2% | Jun 25, 2026 | Huly Platform through 0.7.423, fixed in commit 68cbf8a contains an authenticated server-side request forgery vulnerabili... |
| CVE-2026-56768 | HIGH | 8.8 | 0.4% | Jun 25, 2026 | Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthe... |
| CVE-2026-56767 | HIGH | 8.8 | 0.3% | Jun 25, 2026 | Maxun before 0.0.42 contains a cross-tenant insecure direct object reference vulnerability in storage and webhook API ha... |
| CVE-2026-56766 | HIGH | 8.8 | 1.3% | Jun 25, 2026 | Hydra through 9.7, fixed in commit 9cc84c2, contains a stack buffer overflow in NTLM authentication across SMTP, POP3, I... |
| CVE-2026-55667 | HIGH | 8.2 | 0.4% | Jun 25, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-54917 | CRITICAL | 10 | 0.3% | Jun 25, 2026 | SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the ... |
| CVE-2026-54250 | MEDIUM | 5.8 | 0.1% | Jun 25, 2026 | K3s is a fully conformant production-ready Kubernetes distribution. Prior to 1.35.3+k3s1, 1.34.6+k3s1, v1.33.10+k3s1, a ... |
| CVE-2026-54097 | HIGH | 7.2 | 0.4% | Jun 25, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-54096 | HIGH | 8.4 | 0.2% | Jun 25, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-54094 | HIGH | 7.5 | 0.5% | Jun 25, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-54093 | MEDIUM | 6.8 | 0.2% | Jun 25, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-54092 | MEDIUM | 6.5 | 0.5% | Jun 25, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-54091 | HIGH | 7.5 | 0.5% | Jun 25, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-54090 | HIGH | 8.7 | 0.3% | Jun 25, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now