2026 CVE Vulnerabilities
60,222 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48138 | HIGH | 8.7 | 0.3% | Jun 19, 2026 | There is an out-of-bounds read vulnerability in the NI grpc-device streaming API due to a missing bounds check that may ... |
| CVE-2026-48137 | CRITICAL | 9.8 | 0.5% | Jun 19, 2026 | There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an a... |
| CVE-2026-47341 | MEDIUM | 6.5 | 0.4% | Jun 19, 2026 | Authentication Bypass by Capture-replay vulnerability in Apache APISIX. Attacker can benefit from certain configuration... |
| CVE-2026-47339 | HIGH | 8.1 | 0.3% | Jun 19, 2026 | Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under defaul... |
| CVE-2026-44915 | MEDIUM | 6.1 | 0.4% | Jun 19, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default configuration of cas-au... |
| CVE-2026-44087 | CRITICAL | 9.1 | 0.2% | Jun 19, 2026 | Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect plugin under default ... |
| CVE-2026-44046 | MEDIUM | 5.8 | 0.3% | Jun 19, 2026 | Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac plugin under defaul... |
| CVE-2026-39999 | CRITICAL | 9.1 | 0.4% | Jun 19, 2026 | Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication cap... |
| CVE-2026-39998 | HIGH | 8.8 | 0.4% | Jun 19, 2026 | Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in f... |
| CVE-2026-12104 | HIGH | 8.6 | 1.1% | Jun 19, 2026 | OS command injection in the environment and tunnel configuration functionality in SIMA GmbH Bondix through version 1.25.... |
| CVE-2026-56142 | HIGH | 8.8 | 0.4% | Jun 19, 2026 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privileg... |
| CVE-2026-56141 | CRITICAL | 9.8 | 0.4% | Jun 19, 2026 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account ... |
| CVE-2026-53915 | HIGH | 8.8 | 0.2% | Jun 19, 2026 | In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration |
| CVE-2026-50242 | CRITICAL | 9.8 | 0.4% | Jun 19, 2026 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authenti... |
| CVE-2026-44939 | CRITICAL | 9.4 | 1.1% | Jun 19, 2026 | A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clus... |
| CVE-2026-12706 | MEDIUM | 6.5 | 0.2% | Jun 19, 2026 | A use-after-free vulnerability was found in FFmpeg's RASC video decoder. The decode_move() function initializes a read p... |
| CVE-2026-11941 | MEDIUM | 5.6 | 0.2% | Jun 19, 2026 | Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The “... |
| CVE-2026-8296 | MEDIUM | 5.6 | 0.2% | Jun 19, 2026 | In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payloa... |
| CVE-2026-56138 | MEDIUM | 5.3 | 0.3% | Jun 19, 2026 | AIL framework contains a path traversal vulnerability in the /objects/item/diff endpoint. The endpoint accepts item iden... |
| CVE-2026-41156 | HIGH | 7.7 | 0.1% | Jun 19, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of reso... |
| CVE-2026-34192 | HIGH | 7.7 | 0.1% | Jun 19, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an error path leading... |
| CVE-2026-11576 | HIGH | 7.5 | 0.3% | Jun 19, 2026 | The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process t... |
| CVE-2026-6798 | MEDIUM | 5.3 | 0.3% | Jun 19, 2026 | The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is vulnerable to unauthorized access in all version... |
| CVE-2026-46461 | HIGH | 7.8 | 0.1% | Jun 19, 2026 | Dell Server Hardware Manager, versions prior to 3.2.2, contains an Improper Access Control vulnerability. A low privileg... |
| CVE-2026-3640 | MEDIUM | 5.3 | 0.4% | Jun 19, 2026 | The STRABL – A checkout solution plugin for WordPress is vulnerable to Missing Authentication in all versions up to and ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now