2026 CVE Vulnerabilities
60,152 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45688 | CRITICAL | 9.1 | 0.3% | Jun 24, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, ... |
| CVE-2026-45687 | HIGH | 8.5 | 0.2% | Jun 24, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, ... |
| CVE-2026-45677 | HIGH | 8.7 | 0.5% | Jun 24, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, ... |
| CVE-2026-33543 | CRITICAL | 9.3 | 0.3% | Jun 24, 2026 | FOSSBilling is a free, open-source billing and client management system. Versions 0.7.2 and prior expose a guest API end... |
| CVE-2026-33235 | HIGH | 7.7 | 0.3% | Jun 24, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent... |
| CVE-2026-32315 | MEDIUM | 5.5 | 2.9% | Jun 24, 2026 | motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Version... |
| CVE-2026-31978 | MEDIUM | 6.5 | 0.4% | Jun 24, 2026 | motionEye (mEye) is an online interface for motion software, which is a video surveillance program with motion detection... |
| CVE-2026-25119 | HIGH | 7.7 | 0.9% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, when ENABLE_REVERSE_PROXY_AUTHENTICATION is enabled, Go... |
| CVE-2026-1840 | HIGH | 8.7 | 0.7% | Jun 24, 2026 | The Aclara Metrum Cellular Web Interface is vulnerable to unauthorized access due to the absence of authentication contr... |
| CVE-2026-13208 | MEDIUM | 6.5 | 0.1% | Jun 24, 2026 | A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SE... |
| CVE-2026-13201 | HIGH | 7.3 | 0.2% | Jun 24, 2026 | A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW... |
| CVE-2026-11998 | HIGH | 7.6 | 0.3% | Jun 24, 2026 | A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and ... |
| CVE-2026-55583 | HIGH | 7.6 | 0.2% | Jun 24, 2026 | Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.9.0, Twenty was vulnerable to a cro... |
| CVE-2026-48028 | MEDIUM | 6.5 | 0.1% | Jun 24, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodo... |
| CVE-2026-47389 | HIGH | 8.6 | 0.2% | Jun 24, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, when us... |
| CVE-2026-46349 | MEDIUM | 5.3 | 0.2% | Jun 24, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodo... |
| CVE-2026-46348 | HIGH | 8.7 | 0.3% | Jun 24, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, the lis... |
| CVE-2026-27708 | HIGH | 7.1 | 0.3% | Jun 24, 2026 | FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom ... |
| CVE-2026-23879 | HIGH | 8 | 0.4% | Jun 24, 2026 | py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryptio... |
| CVE-2026-53950 | HIGH | 7.5 | 0.2% | Jun 24, 2026 | @tryghost/activitypub is Ghost’s social/federation client app. Prior to 3.1.0, the ActivityPub client in Ghost was vulne... |
| CVE-2026-53949 | MEDIUM | 5.3 | 0.2% | Jun 24, 2026 | Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public ... |
| CVE-2026-53948 | MEDIUM | 5.4 | 0.1% | Jun 24, 2026 | Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied C... |
| CVE-2026-53947 | MEDIUM | 5.3 | 0.2% | Jun 24, 2026 | Ghost is a Node.js content management system. From 5.18.0 until 6.21.1, a discrepancy in responses from the members sign... |
| CVE-2026-53946 | MEDIUM | 5.4 | 0.1% | Jun 24, 2026 | Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, when re-rendering posts, Ghost would refetch mis... |
| CVE-2026-53945 | MEDIUM | 4 | 0.1% | Jun 24, 2026 | Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghost’s private-IP check for outbound HTTP reques... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now