2026 CVE Vulnerabilities
60,215 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56425 | HIGH | 8.8 | 0.3% | Jun 22, 2026 | The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorizat... |
| CVE-2026-56424 | HIGH | 8.8 | 0.4% | Jun 22, 2026 | MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong ent... |
| CVE-2026-56423 | HIGH | 8.8 | 0.3% | Jun 22, 2026 | MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The af... |
| CVE-2026-54100 | HIGH | 8.3 | 0.3% | Jun 22, 2026 | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishe... |
| CVE-2026-54099 | HIGH | 8.8 | 0.1% | Jun 22, 2026 | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR au... |
| CVE-2026-42129 | HIGH | 7.7 | 0.4% | Jun 22, 2026 | A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endp... |
| CVE-2026-28381 | HIGH | 8.1 | 0.2% | Jun 22, 2026 | The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the da... |
| CVE-2026-12888 | LOW | 2 | 0.3% | Jun 22, 2026 | An HTML injection vulnerability exists in the Google Chat webhook notification sent by Thinkst Applied Research Canaryt... |
| CVE-2026-12602 | HIGH | 8.8 | 0.1% | Jun 22, 2026 | Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assig... |
| CVE-2026-10601 | MEDIUM | 4.3 | 0.3% | Jun 22, 2026 | A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach uni... |
| CVE-2026-10561 | CRITICAL | 10 | 0.5% | Jun 22, 2026 | IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with... |
| CVE-2026-56422 | CRITICAL | 9.4 | 0.4% | Jun 22, 2026 | Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (i... |
| CVE-2026-11373 | CRITICAL | 9.1 | 0.4% | Jun 22, 2026 | Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for th... |
| CVE-2026-12863 | MEDIUM | 5.1 | 0.2% | Jun 22, 2026 | An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using... |
| CVE-2026-12862 | MEDIUM | 5.1 | 0.2% | Jun 22, 2026 | Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be... |
| CVE-2026-12581 | HIGH | 7.7 | 0.3% | Jun 22, 2026 | EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a s... |
| CVE-2026-12580 | MEDIUM | 5.4 | 0.2% | Jun 22, 2026 | EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attack... |
| CVE-2026-54665 | MEDIUM | 5.3 | 0.3% | Jun 22, 2026 | Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an... |
| CVE-2026-44914 | HIGH | 7.2 | 0.4% | Jun 22, 2026 | Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension componen... |
| CVE-2026-44913 | HIGH | 7.2 | 0.4% | Jun 22, 2026 | Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.... |
| CVE-2026-44911 | MEDIUM | 6.3 | 0.3% | Jun 22, 2026 | Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clie... |
| CVE-2026-8157 | HIGH | 8.8 | 0.2% | Jun 22, 2026 | The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new u... |
| CVE-2026-7859 | MEDIUM | 5.3 | 0.1% | Jun 22, 2026 | The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX action... |
| CVE-2026-6858 | HIGH | 7.1 | 0.2% | Jun 22, 2026 | The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthen... |
| CVE-2026-4259 | HIGH | 7.1 | 0.1% | Jun 22, 2026 | The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outp... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now