2026 CVE Vulnerabilities
60,222 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56080 | MEDIUM | 6.9 | 0.3% | Jun 19, 2026 | Capgo before 12.128.2 contains a flaw in the Enforce Password Policy feature: after a Super Admin enables the policy and... |
| CVE-2026-56079 | HIGH | 7.1 | 0.2% | Jun 19, 2026 | Capgo before 12.128.2 contains a cross-tenant authorization bypass vulnerability in PostgREST endpoints that allows org-... |
| CVE-2026-56073 | CRITICAL | 9.4 | 0.2% | Jun 19, 2026 | Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypa... |
| CVE-2026-50559 | HIGH | 7.5 | 0.5% | Jun 19, 2026 | Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, ... |
| CVE-2026-50519 | HIGH | 7.5 | 0.5% | Jun 19, 2026 | Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized at... |
| CVE-2026-49346 | HIGH | 7.1 | 0.2% | Jun 19, 2026 | libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream wi... |
| CVE-2026-49337 | MEDIUM | 4.3 | 0.2% | Jun 19, 2026 | libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265... |
| CVE-2026-49295 | HIGH | 7.1 | 0.2% | Jun 19, 2026 | libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream c... |
| CVE-2026-48794 | LOW | 1.3 | 0.3% | Jun 19, 2026 | Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-o... |
| CVE-2026-48584 | HIGH | 8.8 | 0.5% | Jun 19, 2026 | Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a networ... |
| CVE-2026-48582 | CRITICAL | 9.6 | 0.4% | Jun 19, 2026 | Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-48129 | MEDIUM | 6.5 | 0.3% | Jun 19, 2026 | Kestra is an open-source, event-driven orchestration platform. Prior to versions 1.3.19, 1.2.19, 1.1.19, and 1.0.43, Kes... |
| CVE-2026-47645 | HIGH | 8.8 | 0.4% | Jun 19, 2026 | Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized atta... |
| CVE-2026-47203 | LOW | 2.9 | 0.3% | Jun 19, 2026 | Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-o... |
| CVE-2026-45480 | CRITICAL | 10 | 0.6% | Jun 19, 2026 | Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-42895 | HIGH | 7.5 | 0.4% | Jun 19, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut... |
| CVE-2026-32208 | MEDIUM | 5.4 | 0.3% | Jun 19, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an aut... |
| CVE-2026-49345 | MEDIUM | 5.3 | 0.5% | Jun 19, 2026 | Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, ... |
| CVE-2026-49344 | HIGH | 7.1 | 0.3% | Jun 19, 2026 | Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, ... |
| CVE-2026-49342 | MEDIUM | 5.3 | 0.3% | Jun 19, 2026 | YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache ... |
| CVE-2026-48787 | HIGH | 7.4 | 0.5% | Jun 19, 2026 | gin-vue-admin is an AI-assisted basic development platform. In version 2.9.1, an authenticated attacker with access to t... |
| CVE-2026-48774 | HIGH | 7.5 | 0.4% | Jun 19, 2026 | ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 3.0.0 through 3.0.8, ProxySQL's GenAI/MC... |
| CVE-2026-48773 | CRITICAL | 9.8 | 0.7% | Jun 19, 2026 | ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-authenticat... |
| CVE-2026-48772 | CRITICAL | 10 | 0.2% | Jun 19, 2026 | ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL ... |
| CVE-2026-48715 | HIGH | 8.8 | 0.2% | Jun 19, 2026 | radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the `radvdump` utility shipped with radvd contai... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now