2026 CVE Vulnerabilities
60,243 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56021 | MEDIUM | 6.9 | 0.5% | Jun 18, 2026 | Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due ... |
| CVE-2026-56020 | CRITICAL | 9.2 | 0.5% | Jun 18, 2026 | The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL clie... |
| CVE-2026-55237 | HIGH | 8.8 | 0.2% | Jun 18, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent... |
| CVE-2026-55205 | MEDIUM | 6.9 | 0.3% | Jun 18, 2026 | Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oa... |
| CVE-2026-55204 | HIGH | 8.7 | 0.4% | Jun 18, 2026 | HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert()... |
| CVE-2026-55203 | CRITICAL | 9.1 | 0.3% | Jun 18, 2026 | HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's ... |
| CVE-2026-54106 | MEDIUM | 5.1 | 0.3% | Jun 18, 2026 | The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac... |
| CVE-2026-54105 | MEDIUM | 6.9 | 0.3% | Jun 18, 2026 | The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac... |
| CVE-2026-54104 | HIGH | 8.8 | 0.4% | Jun 18, 2026 | The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac... |
| CVE-2026-54103 | CRITICAL | 9.8 | 0.4% | Jun 18, 2026 | The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac... |
| CVE-2026-48617 | HIGH | 8.2 | 0.2% | Jun 18, 2026 | A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This... |
| CVE-2026-38718 | HIGH | 7.5 | 0.3% | Jun 18, 2026 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a bu... |
| CVE-2026-38717 | CRITICAL | 9.8 | 1.3% | Jun 18, 2026 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a co... |
| CVE-2026-38716 | CRITICAL | 9.8 | 1.3% | Jun 18, 2026 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a co... |
| CVE-2026-38715 | CRITICAL | 9.8 | 1.3% | Jun 18, 2026 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a co... |
| CVE-2026-38714 | CRITICAL | 9.8 | 1.3% | Jun 18, 2026 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a co... |
| CVE-2026-11982 | MEDIUM | 5.1 | 0.3% | Jun 18, 2026 | Grav 2.0.0-rc.9 with Admin2 2.0.0-rc.14 contains a stored cross-site scripting (XSS) vulnerability in the Admin2 Pages A... |
| CVE-2026-10687 | — | — | — | Jun 18, 2026 | Rejected reason: This CVE Record has been rejected by the Zephyr Project CNA. Subsequent analysis, confirmed with the fi... |
| CVE-2026-46580 | HIGH | 8.8 | 0.3% | Jun 18, 2026 | In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were auto... |
| CVE-2026-44691 | HIGH | 8.8 | 0.2% | Jun 18, 2026 | In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/t... |
| CVE-2026-44688 | HIGH | 8.8 | 0.3% | Jun 18, 2026 | In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its... |
| CVE-2026-22551 | MEDIUM | 6.5 | 0.2% | Jun 18, 2026 | In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP r... |
| CVE-2026-11791 | MEDIUM | 5 | 0.3% | Jun 18, 2026 | A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees... |
| CVE-2026-9158 | CRITICAL | 9.8 | 0.2% | Jun 18, 2026 | In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interfac... |
| CVE-2026-8461 | HIGH | 8.8 | 0.5% | Jun 18, 2026 | An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now