2026 CVE Vulnerabilities
60,151 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7569 | HIGH | 8.8 | 0.7% | Jun 25, 2026 | Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows rem... |
| CVE-2026-40079 | CRITICAL | 9.8 | 1.1% | Jun 25, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command ... |
| CVE-2026-39951 | HIGH | 8.8 | 0.2% | Jun 25, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a Stored SQL Injectio... |
| CVE-2026-39955 | CRITICAL | 9.8 | 0.3% | Jun 24, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQ... |
| CVE-2026-39948 | CRITICAL | 9.8 | 0.5% | Jun 24, 2026 | Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request pa... |
| CVE-2026-39938 | CRITICAL | 9.8 | 0.4% | Jun 24, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI t... |
| CVE-2026-39900 | MEDIUM | 6.1 | 0.2% | Jun 24, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Reflecte... |
| CVE-2026-39899 | MEDIUM | 5.3 | 0.3% | Jun 24, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Tra... |
| CVE-2026-9779 | HIGH | 7.2 | 0.4% | Jun 24, 2026 | ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability.... |
| CVE-2026-9778 | HIGH | 7.2 | 1.5% | Jun 24, 2026 | ATEN Unizon ImportDeviceList Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote a... |
| CVE-2026-9777 | HIGH | 7.2 | 1.5% | Jun 24, 2026 | ATEN Unizon restoreDB Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attacker... |
| CVE-2026-9776 | HIGH | 7.5 | 1.6% | Jun 24, 2026 | ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Disclosure Vulnerability. This vulnerability ... |
| CVE-2026-9775 | MEDIUM | 6.5 | 1.2% | Jun 24, 2026 | ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attack... |
| CVE-2026-9774 | MEDIUM | 6.5 | 1.2% | Jun 24, 2026 | ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote at... |
| CVE-2026-9773 | HIGH | 8.8 | 1.1% | Jun 24, 2026 | Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote at... |
| CVE-2026-9772 | HIGH | 8.8 | 1.1% | Jun 24, 2026 | Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote att... |
| CVE-2026-55762 | HIGH | 8.1 | 0.3% | Jun 24, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, ... |
| CVE-2026-55759 | HIGH | 7.4 | 0.2% | Jun 24, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, ... |
| CVE-2026-55666 | CRITICAL | 9.3 | 0.3% | Jun 24, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, ... |
| CVE-2026-55570 | CRITICAL | 9 | 0.3% | Jun 24, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (... |
| CVE-2026-55455 | CRITICAL | 9.1 | 0.2% | Jun 24, 2026 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the outbound HTTP host filte... |
| CVE-2026-55454 | CRITICAL | 9.9 | 0.3% | Jun 24, 2026 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-pr... |
| CVE-2026-54759 | HIGH | 8.7 | 0.3% | Jun 24, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, Lute's HTML sanitizer does not remove <if... |
| CVE-2026-54158 | CRITICAL | 9.9 | 0.3% | Jun 24, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell render... |
| CVE-2026-54070 | HIGH | 7.1 | 0.2% | Jun 24, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, renderPackageREADME in kernel/bazaar/read... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now