2026 CVE Vulnerabilities
60,149 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54844 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions. |
| CVE-2026-54843 | CRITICAL | 9.3 | 0.2% | Jun 25, 2026 | Unauthenticated SQL Injection in MDTF <= 1.3.7 versions. |
| CVE-2026-54842 | HIGH | 8.1 | 0.2% | Jun 25, 2026 | Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2026-54841 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions. |
| CVE-2026-54838 | HIGH | 8.5 | 0.3% | Jun 25, 2026 | Subscriber SQL Injection in WC Vendors Marketplace <= 2.6.8 versions. |
| CVE-2026-54836 | CRITICAL | 9.3 | 0.2% | Jun 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows ... |
| CVE-2026-54830 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions. |
| CVE-2026-54829 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt... |
| CVE-2026-54828 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | Unauthenticated Broken Access Control in Motors <= 1.4.109 versions. |
| CVE-2026-54823 | CRITICAL | 9.9 | 0.4% | Jun 25, 2026 | Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions. |
| CVE-2026-54822 | HIGH | 8.5 | 0.3% | Jun 25, 2026 | Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions. |
| CVE-2026-54821 | HIGH | 7.4 | 0.3% | Jun 25, 2026 | Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions. |
| CVE-2026-52690 | MEDIUM | 5.9 | 0.4% | Jun 25, 2026 | Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of D... |
| CVE-2026-4526 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logi... |
| CVE-2026-49506 | HIGH | 7.2 | 0.5% | Jun 25, 2026 | Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted ... |
| CVE-2026-47154 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating ... |
| CVE-2026-47153 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, a malformed Level Control Step command can terminate the process through a divide-by-ze... |
| CVE-2026-47152 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, a malformed Level Control Move command can terminate the process through a divide-by-ze... |
| CVE-2026-47151 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock... |
| CVE-2026-47150 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write a... |
| CVE-2026-47149 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed or out-of-range Door Lock user identifiers can trigger out-of-bounds table re... |
| CVE-2026-47148 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed GetGroupMembership commands can trigger repeated reads past the end of the me... |
| CVE-2026-47147 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limi... |
| CVE-2026-47146 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These ... |
| CVE-2026-47145 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed Color Control messages can lead to asserts that terminate the process. These ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now