2026 CVE Vulnerabilities
60,222 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49260 | HIGH | 8.2 | 0.2% | Jun 19, 2026 | PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.5.1, `pontedilana/... |
| CVE-2026-3196 | MEDIUM | 5.5 | 0.1% | Jun 19, 2026 | An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious g... |
| CVE-2026-3195 | HIGH | 7.4 | 0.2% | Jun 19, 2026 | A flaw was found in QEMU. When reading input audio in the virtio-snd device input callback, the `virtio_snd_pcm_in_cb` f... |
| CVE-2026-12622 | MEDIUM | 5.4 | 0.2% | Jun 19, 2026 | The GridTime 3000 GNSS Time Server has an open redirect vulnerability in the password change form submission. This issu... |
| CVE-2026-12621 | MEDIUM | 5.4 | 0.2% | Jun 19, 2026 | Improper neutralization of input during web page generation XSS vulnerability in the GridTime 3000 (password reset form... |
| CVE-2026-12620 | MEDIUM | 6.5 | 0.2% | Jun 19, 2026 | The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints. This issue affects G... |
| CVE-2026-12619 | MEDIUM | 5.4 | 0.2% | Jun 19, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Microchip G... |
| CVE-2026-52910 | HIGH | 7.8 | 0.1% | Jun 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace perio... |
| CVE-2026-52909 | HIGH | 7.8 | 0.1% | Jun 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: ip6_vti: set netns_immutable on the fallback device... |
| CVE-2026-52908 | HIGH | 7.8 | 0.1% | Jun 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA: During rereg_mr ensure that REREG_ACCESS is c... |
| CVE-2026-49358 | LOW | 3 | 0.1% | Jun 19, 2026 | PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `AbstractGene... |
| CVE-2026-21768 | MEDIUM | 6.3 | 0.1% | Jun 19, 2026 | The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to prope... |
| CVE-2026-9143 | MEDIUM | 5.3 | 0.2% | Jun 19, 2026 | There is an incorrect conversion between numeric types vulnerability in NI grpc-device due to missing range checks in Co... |
| CVE-2026-9142 | CRITICAL | 9.3 | 0.3% | Jun 19, 2026 | There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the s... |
| CVE-2026-4027 | HIGH | 7.1 | 0.2% | Jun 19, 2026 | A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 and R2 that could allow unauthorized acces... |
| CVE-2026-4026 | HIGH | 8.7 | 0.3% | Jun 19, 2026 | A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 that could allow an authenticated user wit... |
| CVE-2026-49872 | HIGH | 8.1 | 0.3% | Jun 19, 2026 | Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route, an attacker can po... |
| CVE-2026-49871 | CRITICAL | 9.3 | 0.3% | Jun 19, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows... |
| CVE-2026-49357 | HIGH | 8.8 | 0.3% | Jun 19, 2026 | Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly o... |
| CVE-2026-49231 | MEDIUM | 5.4 | 0.4% | Jun 19, 2026 | Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed identity headers to upst... |
| CVE-2026-49230 | CRITICAL | 9.1 | 0.2% | Jun 19, 2026 | Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default confi... |
| CVE-2026-48895 | HIGH | 7.2 | 0.4% | Jun 19, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some ... |
| CVE-2026-48141 | HIGH | 7.5 | 0.2% | Jun 19, 2026 | There is a memory leak in NI grpc-device BeginSidebandStream that may result in denial of service due to memory exhausti... |
| CVE-2026-48140 | HIGH | 7.1 | 0.3% | Jun 19, 2026 | There is an unchecked enum cast vulnerability in NI grpc-device BeginSidebandStream that may allow an attacker to trigge... |
| CVE-2026-48139 | HIGH | 8.7 | 0.3% | Jun 19, 2026 | There is a NULL pointer dereference vulnerability in NI grpc-device in the data moniker service that may allow an attack... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now