2026 CVE Vulnerabilities
60,210 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12549 | MEDIUM | 4.8 | 0.3% | Jun 22, 2026 | The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a gene... |
| CVE-2026-12479 | MEDIUM | 6.1 | 0.3% | Jun 22, 2026 | A path traversal vulnerability exists in keras-team/keras version 3.14.0, specifically in the `DiskIOStore.make` method ... |
| CVE-2026-11943 | MEDIUM | 4.8 | 0.3% | Jun 22, 2026 | Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the document timeline shown on i... |
| CVE-2026-11942 | MEDIUM | 4.8 | 0.3% | Jun 22, 2026 | Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the reusable delete confirmation... |
| CVE-2026-11372 | MEDIUM | 5.4 | 0.2% | Jun 22, 2026 | IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an... |
| CVE-2026-10845 | HIGH | 7.3 | 0.3% | Jun 22, 2026 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorize... |
| CVE-2026-9162 | MEDIUM | 4.3 | 0.2% | Jun 22, 2026 | Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to invalidate cached ... |
| CVE-2026-9029 | MEDIUM | 5.4 | 0.3% | Jun 22, 2026 | A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer ... |
| CVE-2026-8074 | LOW | 3.8 | 0.2% | Jun 22, 2026 | Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user act... |
| CVE-2026-7167 | MEDIUM | 6.9 | 0.4% | Jun 22, 2026 | The vulnerability arises when the system fails to properly validate the 'email' field during the authentication process,... |
| CVE-2026-7166 | CRITICAL | 9.2 | 0.4% | Jun 22, 2026 | Vulnerability involving the exposure of sensitive data provided without adequate protection. The API exposes email and p... |
| CVE-2026-7165 | CRITICAL | 9.4 | 0.3% | Jun 22, 2026 | The vulnerability is present in the ‘/addJugador’ endpoint: * The 'keyJugador' and 'keyJugadorObjectiu' parameters a... |
| CVE-2026-6673 | MEDIUM | 6.4 | 0.2% | Jun 22, 2026 | Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to authenticate Atlas... |
| CVE-2026-6653 | CRITICAL | 9.8 | 0.3% | Jun 22, 2026 | Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker ... |
| CVE-2026-6062 | MEDIUM | 6.4 | 0.2% | Jun 22, 2026 | Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 Fail to validate channel o... |
| CVE-2026-5139 | MEDIUM | 5.4 | 0.2% | Jun 22, 2026 | Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to enforce administra... |
| CVE-2026-56450 | MEDIUM | 5.1 | 0.3% | Jun 22, 2026 | AIL did not restrict repeated failed attempts to verify a two-factor authentication (OTP) code. An attacker who had reac... |
| CVE-2026-56448 | HIGH | 8.3 | 0.3% | Jun 22, 2026 | A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e4... |
| CVE-2026-56447 | HIGH | 7.2 | 0.3% | Jun 22, 2026 | MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path... |
| CVE-2026-56446 | HIGH | 7.2 | 0.4% | Jun 22, 2026 | MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool... |
| CVE-2026-56425 | HIGH | 8.8 | 0.3% | Jun 22, 2026 | The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorizat... |
| CVE-2026-56424 | HIGH | 8.8 | 0.4% | Jun 22, 2026 | MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong ent... |
| CVE-2026-56423 | HIGH | 8.8 | 0.3% | Jun 22, 2026 | MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The af... |
| CVE-2026-54100 | HIGH | 8.3 | 0.3% | Jun 22, 2026 | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishe... |
| CVE-2026-54099 | HIGH | 8.8 | 0.1% | Jun 22, 2026 | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR au... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now