2026 CVE Vulnerabilities
60,210 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53538 | LOW | 3.7 | 0.2% | Jun 22, 2026 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field sep... |
| CVE-2026-53537 | MEDIUM | 5.3 | 0.2% | Jun 22, 2026 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Dispos... |
| CVE-2026-50556 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-50555 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-50269 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled inp... |
| CVE-2026-50184 | MEDIUM | 6.1 | 0.1% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-50171 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-50170 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-50169 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-50168 | HIGH | 8.2 | 0.2% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-49356 | LOW | 3.6 | 0.1% | Jun 22, 2026 | Babel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an a... |
| CVE-2026-48712 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.1 and 8.4.1, protobufjs could recu... |
| CVE-2026-46417 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-42127 | HIGH | 7.5 | 0.4% | Jun 22, 2026 | The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attacke... |
| CVE-2026-12249 | CRITICAL | 9 | 0.1% | Jun 22, 2026 | An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active Directory Certificate Servic... |
| CVE-2026-11994 | MEDIUM | 4.8 | 0.3% | Jun 22, 2026 | Akaunting 3.1.21 contains an authenticated stored Cross-Site Scripting vulnerability in the report management workflow. ... |
| CVE-2026-11825 | — | — | — | Jun 22, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2026-10789 | CRITICAL | 9.6 | 0.3% | Jun 22, 2026 | A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled... |
| CVE-2026-9610 | MEDIUM | 5.3 | 0.1% | Jun 22, 2026 | IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality... |
| CVE-2026-9320 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 a... |
| CVE-2026-9072 | CRITICAL | 9.8 | 0.4% | Jun 22, 2026 | IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with t... |
| CVE-2026-9071 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 a... |
| CVE-2026-9006 | CRITICAL | 9.1 | 0.2% | Jun 22, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy co... |
| CVE-2026-8934 | MEDIUM | 6.9 | 0.4% | Jun 22, 2026 | A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud C... |
| CVE-2026-8858 | HIGH | 8.8 | 0.3% | Jun 22, 2026 | IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution an... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now