2026 CVE Vulnerabilities
60,151 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54069 | CRITICAL | 9.2 | 0.6% | Jun 24, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan Note's kernel HTTP server uncondit... |
| CVE-2026-54068 | MEDIUM | 5.9 | 0.2% | Jun 24, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the /api/icon/getDynamicIcon endpoint is ... |
| CVE-2026-54067 | CRITICAL | 9.9 | 0.3% | Jun 24, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> brea... |
| CVE-2026-54066 | HIGH | 7.5 | 1.9% | Jun 24, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the patch for CVE-2026-41894 ("Path Trave... |
| CVE-2026-53766 | MEDIUM | 6.1 | 0.1% | Jun 24, 2026 | Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From ... |
| CVE-2026-53765 | MEDIUM | 6.1 | 0.1% | Jun 24, 2026 | Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From ... |
| CVE-2026-52794 | HIGH | 7.5 | 0.3% | Jun 24, 2026 | Sentry is an error tracking and performance monitoring tool. From 24.4.0 until 26.5.2, a Regular Expression Denial of Se... |
| CVE-2026-50551 | CRITICAL | 9.9 | 0.4% | Jun 24, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scrip... |
| CVE-2026-50189 | HIGH | 7.2 | 0.2% | Jun 24, 2026 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, Appsmith's bundled superviso... |
| CVE-2026-49979 | LOW | 2.7 | 0.3% | Jun 24, 2026 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.99, the POST /api/v1/admin/send... |
| CVE-2026-47110 | HIGH | 7.1 | 0.3% | Jun 24, 2026 | Tiptap for PHP before version 2.1.1 contains an input validation vulnerability that allows authenticated attackers to ca... |
| CVE-2026-47093 | — | — | — | Jun 24, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-39897 | MEDIUM | 6.1 | 0.2% | Jun 24, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and below contain a Reflected XSS vu... |
| CVE-2026-39894 | LOW | 2.5 | 0.1% | Jun 24, 2026 | Cacti is an open source performance and fault management framework. In versions 1.2.30 and below, the locale-dependent d... |
| CVE-2026-39893 | CRITICAL | 9.8 | 0.4% | Jun 24, 2026 | Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request va... |
| CVE-2026-2050 | HIGH | 7.8 | 0.6% | Jun 24, 2026 | GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a... |
| CVE-2026-10642 | MEDIUM | 4.6 | 0.2% | Jun 24, 2026 | The Zephyr PL011 UART driver (drivers/serial/uart_pl011.c) contains an unbounded software loop in pl011_irq_tx_enable() ... |
| CVE-2026-10043 | HIGH | 7.8 | 0.3% | Jun 24, 2026 | MosaicML Composer Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remot... |
| CVE-2026-7539 | HIGH | 7.3 | 0.1% | Jun 24, 2026 | A potential security vulnerability has been identified in the HP Accessory WMI Provider installer for some HP Docking St... |
| CVE-2026-52816 | MEDIUM | 5.4 | 0.7% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Jupyter Notebook (ipynb) sanitizer endpoint at POST... |
| CVE-2026-52815 | MEDIUM | 5.5 | 1.6% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs has an unauthenticated information disclosure vuln... |
| CVE-2026-52814 | MEDIUM | 5.5 | 0.5% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs built-in Go SSH server is vulnerable to an una... |
| CVE-2026-52813 | CRITICAL | 10 | 1.1% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences ... |
| CVE-2026-52812 | HIGH | 7.1 | 0.2% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git LFS storage is content-addressed by OID alone (<LFS... |
| CVE-2026-52811 | CRITICAL | 9 | 0.5% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now