2026 CVE Vulnerabilities
60,243 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44915 | MEDIUM | 6.1 | 0.4% | Jun 19, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default configuration of cas-au... |
| CVE-2026-44087 | CRITICAL | 9.1 | 0.2% | Jun 19, 2026 | Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect plugin under default ... |
| CVE-2026-44046 | MEDIUM | 5.8 | 0.3% | Jun 19, 2026 | Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac plugin under defaul... |
| CVE-2026-39999 | CRITICAL | 9.1 | 0.4% | Jun 19, 2026 | Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication cap... |
| CVE-2026-39998 | HIGH | 8.8 | 0.4% | Jun 19, 2026 | Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in f... |
| CVE-2026-12104 | HIGH | 8.6 | 1.1% | Jun 19, 2026 | OS command injection in the environment and tunnel configuration functionality in SIMA GmbH Bondix through version 1.25.... |
| CVE-2026-56142 | HIGH | 8.8 | 0.4% | Jun 19, 2026 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privileg... |
| CVE-2026-56141 | CRITICAL | 9.8 | 0.4% | Jun 19, 2026 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account ... |
| CVE-2026-53915 | HIGH | 8.8 | 0.2% | Jun 19, 2026 | In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration |
| CVE-2026-50242 | CRITICAL | 9.8 | 0.4% | Jun 19, 2026 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authenti... |
| CVE-2026-44939 | CRITICAL | 9.4 | 1.1% | Jun 19, 2026 | A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clus... |
| CVE-2026-12706 | MEDIUM | 6.5 | 0.2% | Jun 19, 2026 | A use-after-free vulnerability was found in FFmpeg's RASC video decoder. The decode_move() function initializes a read p... |
| CVE-2026-11941 | MEDIUM | 5.6 | 0.2% | Jun 19, 2026 | Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The “... |
| CVE-2026-8296 | MEDIUM | 5.6 | 0.2% | Jun 19, 2026 | In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payloa... |
| CVE-2026-56138 | MEDIUM | 5.3 | 0.3% | Jun 19, 2026 | AIL framework contains a path traversal vulnerability in the /objects/item/diff endpoint. The endpoint accepts item iden... |
| CVE-2026-41156 | HIGH | 7.7 | 0.1% | Jun 19, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of reso... |
| CVE-2026-34192 | HIGH | 7.7 | 0.1% | Jun 19, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an error path leading... |
| CVE-2026-11576 | HIGH | 7.5 | 0.3% | Jun 19, 2026 | The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process t... |
| CVE-2026-6798 | MEDIUM | 5.3 | 0.3% | Jun 19, 2026 | The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is vulnerable to unauthorized access in all version... |
| CVE-2026-46461 | HIGH | 7.8 | 0.1% | Jun 19, 2026 | Dell Server Hardware Manager, versions prior to 3.2.2, contains an Improper Access Control vulnerability. A low privileg... |
| CVE-2026-3640 | MEDIUM | 5.3 | 0.4% | Jun 19, 2026 | The STRABL – A checkout solution plugin for WordPress is vulnerable to Missing Authentication in all versions up to and ... |
| CVE-2026-9822 | MEDIUM | 6.5 | 0.2% | Jun 19, 2026 | The WP Hotel Booking WordPress plugin before 2.3.1 does not enforce capability checks in several of its AJAX handlers, a... |
| CVE-2026-9013 | MEDIUM | 4.3 | 0.3% | Jun 19, 2026 | The Bogo plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.9.... |
| CVE-2026-8713 | CRITICAL | 9.1 | 1.2% | Jun 19, 2026 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path v... |
| CVE-2026-8118 | MEDIUM | 6.5 | 0.2% | Jun 19, 2026 | The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to Arbitrary ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now