2026 CVE Vulnerabilities
60,200 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46549 | LOW | 2 | 0.2% | Jun 23, 2026 | NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the OAuth token strategy attached oauth_s... |
| CVE-2026-46548 | MEDIUM | 4.3 | 0.2% | Jun 23, 2026 | NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, the request-filtering-agent SSRF protecti... |
| CVE-2026-46547 | MEDIUM | 6.1 | 0.1% | Jun 23, 2026 | NocoDB is software for building databases as spreadsheets. Prior to 2026.04.1, a reflected XSS vulnerability exists in t... |
| CVE-2026-41862 | HIGH | 8.8 | 0.4% | Jun 23, 2026 | Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-ma... |
| CVE-2026-23513 | HIGH | 7.1 | 0.3% | Jun 23, 2026 | FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, a query-constructi... |
| CVE-2026-12892 | MEDIUM | 4.4 | 0.1% | Jun 23, 2026 | A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing... |
| CVE-2026-12891 | MEDIUM | 4.3 | 0.3% | Jun 23, 2026 | A flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream with a cra... |
| CVE-2026-12112 | HIGH | 7.8 | 0.2% | Jun 23, 2026 | A flaw was found in the foreman-mcp-server. A session management vulnerability in the MCP Server allows unauthenticated ... |
| CVE-2026-11820 | MEDIUM | 6.5 | 0.3% | Jun 23, 2026 | A flaw was found in the community.general Ansible collection's nexmo module. The module constructs HTTP requests to the ... |
| CVE-2026-11819 | MEDIUM | 5.5 | 0.2% | Jun 23, 2026 | Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Issue: The module... |
| CVE-2026-11807 | CRITICAL | 9.6 | 0.4% | Jun 23, 2026 | A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible... |
| CVE-2026-54762 | HIGH | 8.6 | 0.2% | Jun 23, 2026 | Traefik is an HTTP reverse proxy and load balancer. From 3.7.0-ea.1 until 3.7.5, there is a medium severity vulnerabilit... |
| CVE-2026-54761 | HIGH | 7.1 | 0.4% | Jun 23, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.21 and 3.7.5, there is a high severity vulnerability in... |
| CVE-2026-54555 | HIGH | 7.8 | 0.1% | Jun 23, 2026 | rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.42.2, the permission splitter ... |
| CVE-2026-54328 | HIGH | 7.3 | 0.1% | Jun 23, 2026 | Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi versions with temporary npm or git extension packa... |
| CVE-2026-54327 | LOW | 2.2 | 0.1% | Jun 23, 2026 | Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi stored API keys and OAuth credentials in auth.json... |
| CVE-2026-54326 | LOW | 2.5 | 0.1% | Jun 23, 2026 | Pi is a minimal terminal coding harness. From 0.74.0 until 0.78.1, Pi HTML exports render session Markdown into a static... |
| CVE-2026-54325 | MEDIUM | 4.4 | 0.1% | Jun 23, 2026 | Pi is a minimal terminal coding harness. Pi before 0.79.0 loaded project-local configuration and resources from a reposi... |
| CVE-2026-53622 | CRITICAL | 10 | 0.4% | Jun 23, 2026 | Traefik is an HTTP reverse proxy and load balancer. Versions prior to 3.7.3, 3.6.18, and 2.11.51 have a critical vulnera... |
| CVE-2026-48491 | CRITICAL | 10 | 0.3% | Jun 23, 2026 | Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Tr... |
| CVE-2026-48020 | CRITICAL | 10 | 0.8% | Jun 23, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulner... |
| CVE-2026-45792 | MEDIUM | 5.5 | 0.1% | Jun 23, 2026 | rtk filters and compresses command outputs before they reach your LLM context. Prior to 0.32.0, RTK (Rust Token Killer) ... |
| CVE-2026-39253 | HIGH | 8.1 | 0.8% | Jun 23, 2026 | An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll a... |
| CVE-2026-55736 | MEDIUM | 5.9 | 0.2% | Jun 23, 2026 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash allows a... |
| CVE-2026-55249 | HIGH | 8.8 | 0.2% | Jun 23, 2026 | @rtk-ai/rtk-rewrite transparently rewrites shell commands executed via OpenClaw's exec tool to their RTK equivalents. In... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now