2026 CVE Vulnerabilities
60,222 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48089 | HIGH | 7.1 | 0.2% | Jun 19, 2026 | DevGuard provides vulnerability management for the full software supply chain. Prior to 1.4.2, on a DevGuard API instanc... |
| CVE-2026-9375 | — | — | 0.3% | Jun 19, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-49340 | HIGH | 8.1 | 0.3% | Jun 19, 2026 | gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, a logic e... |
| CVE-2026-49339 | HIGH | 7.1 | 0.3% | Jun 19, 2026 | gonic is a music streaming server / free-software subsonic server API implementation. The maintainer's fix in commit `6... |
| CVE-2026-49338 | HIGH | 7.1 | 0.2% | Jun 19, 2026 | gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, the Subso... |
| CVE-2026-49336 | MEDIUM | 5.5 | 0.7% | Jun 19, 2026 | @microsoft/kiota-http-fetchlibrary provides TypeScript libraries for Kiota-generated API clients. In versions 1.0.0-prev... |
| CVE-2026-49293 | HIGH | 7.5 | 0.3% | Jun 19, 2026 | js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. Versions up to and including 1.1.0 pa... |
| CVE-2026-49291 | HIGH | 8.1 | 0.3% | Jun 19, 2026 | mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpo... |
| CVE-2026-49288 | MEDIUM | 4.3 | 0.2% | Jun 19, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, an authenticated Con... |
| CVE-2026-27878 | MEDIUM | 6.5 | 0.2% | Jun 19, 2026 | A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive... |
| CVE-2026-12726 | MEDIUM | 6.3 | 0.2% | Jun 19, 2026 | A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull_request webhooks, the controller sto... |
| CVE-2026-12238 | MEDIUM | 5.3 | 0.2% | Jun 19, 2026 | The WP Go Maps – Most Popular Map Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up t... |
| CVE-2026-49359 | MEDIUM | 6.5 | 0.2% | Jun 19, 2026 | PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/... |
| CVE-2026-49290 | HIGH | 7.6 | 0.6% | Jun 19, 2026 | Slopsmith is a self-contained web application for browsing, playing, and practicing Rocksmith 2014 Custom DLC (CDLC). Pr... |
| CVE-2026-49287 | HIGH | 7.4 | 0.3% | Jun 19, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, the fix for CVE-2026... |
| CVE-2026-49286 | HIGH | 8.1 | 0.6% | Jun 19, 2026 | PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/... |
| CVE-2026-49271 | MEDIUM | 6.5 | 0.2% | Jun 19, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder valid... |
| CVE-2026-56211 | HIGH | 7.1 | 0.5% | Jun 19, 2026 | A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds v... |
| CVE-2026-56210 | HIGH | 7.1 | 0.3% | Jun 19, 2026 | A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds ... |
| CVE-2026-56209 | HIGH | 7.1 | 0.3% | Jun 19, 2026 | An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds c... |
| CVE-2026-56208 | HIGH | 7.6 | 0.4% | Jun 19, 2026 | A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 enco... |
| CVE-2026-51846 | CRITICAL | 9.8 | 0.6% | Jun 19, 2026 | In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulne... |
| CVE-2026-51845 | CRITICAL | 9.8 | 0.4% | Jun 19, 2026 | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the m... |
| CVE-2026-51844 | CRITICAL | 9.8 | 0.4% | Jun 19, 2026 | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the c... |
| CVE-2026-51843 | CRITICAL | 9.8 | 0.4% | Jun 19, 2026 | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the w... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now