2026 CVE Vulnerabilities
60,172 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56232 | HIGH | 8.8 | 0.3% | Jun 24, 2026 | Capgo before 12.128.2 fails to enforce limited_to_orgs and limited_to_apps constraints on subkeys provided via x-limited... |
| CVE-2026-56231 | HIGH | 7.6 | 0.2% | Jun 24, 2026 | Capgo before 12.128.2 contains a broken object level authorization (BOLA) vulnerability in the POST /build/start/:jobId ... |
| CVE-2026-56223 | CRITICAL | 9.3 | 0.2% | Jun 24, 2026 | Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that all... |
| CVE-2026-13163 | MEDIUM | 5.3 | 0.3% | Jun 24, 2026 | Open redirect vulnerability (CWE-601) in the _safe_redirect function of the click-tracking endpoint (/c/<token>/) in Mai... |
| CVE-2026-13140 | LOW | 1.1 | 0.2% | Jun 24, 2026 | Stored Cross-Site Scripting in the exposed AWS API key store of Thinkst Applied Research Canarytokens. Anonymous exp... |
| CVE-2026-12242 | HIGH | 8.8 | 0.5% | Jun 24, 2026 | The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and includin... |
| CVE-2026-13150 | MEDIUM | 6.9 | 0.3% | Jun 24, 2026 | Server-Side Request Forgery (SSRF) (CWE-918) in the PDF generation endpoint GET /api/reports/{id}/pdf (backend/main.py) ... |
| CVE-2026-52944 | MEDIUM | 5.5 | 0.1% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix FSCTL permission bypass by adding a perm... |
| CVE-2026-52943 | HIGH | 7.8 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: skbuff: fix missing zerocopy reference in pskb... |
| CVE-2026-11968 | MEDIUM | 5.5 | 0.1% | Jun 24, 2026 | Argument Injection in TortoiseGitBlame via Malicious Git History Filenames Leads to Arbitrary File Write in TortoiseGit |
| CVE-2026-10745 | HIGH | 7.9 | 0.3% | Jun 24, 2026 | Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows... |
| CVE-2026-7761 | HIGH | 8.8 | 0.5% | Jun 24, 2026 | The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset Link Disclosure in all ver... |
| CVE-2026-56052 | HIGH | 7.6 | 0.2% | Jun 24, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel B... |
| CVE-2026-52942 | HIGH | 7.1 | 0.1% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_log: validate MAC header was set befo... |
| CVE-2026-52941 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/smc: avoid NULL deref of conn->lnk in smc_msg_e... |
| CVE-2026-52940 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: tun: zero the whole vnet header in tun_put_user() ... |
| CVE-2026-52939 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/rds: fix NULL deref in rds_ib_send_cqe_handler(... |
| CVE-2026-52938 | MEDIUM | 5.5 | 0.1% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix NULL pointer dereference in bpf_sk_storage... |
| CVE-2026-52937 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: tap: fix stack info leak in tap_ioctl() SIOCGIFHWAD... |
| CVE-2026-52936 | MEDIUM | 5.5 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: jitterentropy - replace long-held spinlock ... |
| CVE-2026-52935 | HIGH | 7.8 | 0.1% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: espintcp: do not reuse an in-progress partial... |
| CVE-2026-52934 | HIGH | 8.8 | 0.2% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: tvlv: reject oversized TVLV packets ba... |
| CVE-2026-52933 | HIGH | 7.8 | 0.1% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: io_uring/poll: fix signed comparison in io_poll_get... |
| CVE-2026-52932 | HIGH | 7.5 | 0.3% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: ipcomp: Free destination pages on acomp error... |
| CVE-2026-52931 | CRITICAL | 9.8 | 0.4% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: avoid use of uninit sender va... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now