2026 CVE Vulnerabilities
60,206 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10711 | HIGH | 8.8 | 0.2% | Jun 23, 2026 | Missing authentication for critical function vulnerability in AKIN Software Computer Import Export Industry and Trade Lt... |
| CVE-2026-4983 | MEDIUM | 5.4 | 0.2% | Jun 23, 2026 | Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content... |
| CVE-2026-11374 | CRITICAL | 9 | 1.2% | Jun 23, 2026 | In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated... |
| CVE-2026-9733 | CRITICAL | 9.1 | 0.3% | Jun 23, 2026 | Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no... |
| CVE-2026-10521 | HIGH | 8.6 | 0.3% | Jun 23, 2026 | An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any user, ... |
| CVE-2026-8379 | HIGH | 7.5 | 0.2% | Jun 23, 2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the file dow... |
| CVE-2026-8378 | MEDIUM | 5.4 | 0.1% | Jun 23, 2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not sanitise nor escape a filename submitted to the ... |
| CVE-2026-8172 | HIGH | 7.1 | 0.2% | Jun 23, 2026 | The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before reflecting it... |
| CVE-2026-8163 | HIGH | 8.8 | 0.2% | Jun 23, 2026 | The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using t... |
| CVE-2026-7842 | MEDIUM | 6.8 | 0.2% | Jun 23, 2026 | The Infility Global Infility Global WordPress plugin before 2.15.20 for WordPress does not sanitize or validate the orde... |
| CVE-2026-12866 | CRITICAL | 9.8 | 0.5% | Jun 23, 2026 | All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execu... |
| CVE-2026-55655 | MEDIUM | 6.1 | 0.1% | Jun 23, 2026 | A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding ... |
| CVE-2026-55654 | LOW | 3.7 | 0.4% | Jun 23, 2026 | A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds read, occurs during the cleanup of GSSAPI (Generic... |
| CVE-2026-55653 | MEDIUM | 6.5 | 0.3% | Jun 23, 2026 | A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group ... |
| CVE-2026-11833 | HIGH | 8.2 | 0.2% | Jun 23, 2026 | Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing t... |
| CVE-2026-10658 | HIGH | 7.1 | 0.2% | Jun 23, 2026 | bt_iso_recv() in subsys/bluetooth/host/iso.c pulled the ISO SDU header (4 bytes) or, when the timestamp flag is set, the... |
| CVE-2026-10651 | MEDIUM | 6.5 | 0.2% | Jun 23, 2026 | bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held the type-... |
| CVE-2026-10645 | MEDIUM | 5.5 | 0.2% | Jun 23, 2026 | The Zephyr ext2 filesystem driver (subsys/fs/ext2) trusted the on-disk directory entry fields de_rec_len and de_name_len... |
| CVE-2026-54236 | MEDIUM | 5.3 | 0.8% | Jun 22, 2026 | vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, the fix for CVE-2026-22778... |
| CVE-2026-54235 | MEDIUM | 6.5 | 0.3% | Jun 22, 2026 | vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, ll temperature validation ... |
| CVE-2026-54233 | MEDIUM | 6.5 | 0.2% | Jun 22, 2026 | vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, vLLM's /v1/audio/transcrip... |
| CVE-2026-54232 | HIGH | 8.8 | 0.3% | Jun 22, 2026 | vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulner... |
| CVE-2026-53923 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | vLLM is an inference and serving engine for large language models (LLMs). From 0.5.5 until 0.23.1rc0, integer truncation... |
| CVE-2026-48746 | CRITICAL | 9.1 | 1.2% | Jun 22, 2026 | vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in AS... |
| CVE-2026-47155 | MEDIUM | 6.5 | 0.1% | Jun 22, 2026 | vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, vLLM's revision pinning contr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now