2026 CVE Vulnerabilities
60,149 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54089 | CRITICAL | 9.1 | 0.3% | Jun 25, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-54088 | CRITICAL | 9.3 | 0.5% | Jun 25, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-53925 | HIGH | 7.8 | 0.2% | Jun 25, 2026 | Glances is an open-source system cross-platform monitoring tool. From 4.0.8 until 4.5.5, the secure_popen() function in ... |
| CVE-2026-50549 | CRITICAL | 9.8 | 0.5% | Jun 25, 2026 | Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by... |
| CVE-2026-50548 | CRITICAL | 9.8 | 0.5% | Jun 25, 2026 | Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by... |
| CVE-2026-4930 | HIGH | 7.1 | 0.1% | Jun 25, 2026 | SYMCRYPTO is the SiXG301's host side hardware engine accessed by PSA crypto library that accelerates symmetric cryptogra... |
| CVE-2026-46611 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s,... |
| CVE-2026-46608 | HIGH | 7.4 | 0.4% | Jun 25, 2026 | Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s)... |
| CVE-2026-46607 | HIGH | 7.8 | 0.3% | Jun 25, 2026 | Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, glances/outdated.py uses pickle.load() ... |
| CVE-2026-46606 | HIGH | 7.8 | 0.2% | Jun 25, 2026 | Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances KVM/QEMU monitoring engine ... |
| CVE-2026-28898 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing t... |
| CVE-2026-12921 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | In AzeoTech DAQFactory versions 21.1 and prior, a Use After Free vulnerability can be exploited by an attacker using spe... |
| CVE-2026-12897 | HIGH | 8.4 | 0.1% | Jun 25, 2026 | Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsin... |
| CVE-2026-6291 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When decrypting PKCS#7 EnvelopedData using RSA PKCS#1 v1.5 key ... |
| CVE-2026-6094 | CRITICAL | 9.1 | 0.3% | Jun 25, 2026 | Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically ... |
| CVE-2026-6091 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | Partial-chain certificate verification may accept chains that terminate at a peer-supplied, untrusted intermediate certi... |
| CVE-2026-55967 | HIGH | 7.5 | 0.1% | Jun 25, 2026 | AES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 GiB) were not properly rejected ... |
| CVE-2026-55961 | HIGH | 7.5 | 0.1% | Jun 25, 2026 | wolfSSL_PKCS7_verify() returning success for a degenerate (certs-only) PKCS#7 object that contains no signer. Such an ob... |
| CVE-2026-55700 | HIGH | 7.1 | 0.3% | Jun 25, 2026 | pnpm is a package manager. From 11.3.0 until 11.5.3, `pnpm stage download` derived a local filename from registry-contro... |
| CVE-2026-55699 | MEDIUM | 6.5 | 0.3% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.2 and 11.5.3, Manifest bin object keys such as "", ".", and ".." passed pnpm's... |
| CVE-2026-55698 | HIGH | 8.8 | 0.2% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first... |
| CVE-2026-55697 | HIGH | 8.8 | 0.1% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can install configDependencies declared in pnpm-workspace.y... |
| CVE-2026-55487 | HIGH | 8.8 | 0.1% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized t... |
| CVE-2026-55180 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repositor... |
| CVE-2026-54679 | MEDIUM | 5.5 | 0.1% | Jun 25, 2026 | jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now