2026 CVE Vulnerabilities
60,251 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10687 | — | — | — | Jun 18, 2026 | Rejected reason: This CVE Record has been rejected by the Zephyr Project CNA. Subsequent analysis, confirmed with the fi... |
| CVE-2026-46580 | HIGH | 8.8 | 0.3% | Jun 18, 2026 | In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in a workspace were auto... |
| CVE-2026-44691 | HIGH | 8.8 | 0.2% | Jun 18, 2026 | In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/t... |
| CVE-2026-44688 | HIGH | 8.8 | 0.3% | Jun 18, 2026 | In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its... |
| CVE-2026-22551 | MEDIUM | 6.5 | 0.2% | Jun 18, 2026 | In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP r... |
| CVE-2026-11791 | MEDIUM | 5 | 0.3% | Jun 18, 2026 | A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees... |
| CVE-2026-9158 | CRITICAL | 9.8 | 0.2% | Jun 18, 2026 | In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interfac... |
| CVE-2026-8461 | HIGH | 8.8 | 0.5% | Jun 18, 2026 | An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial... |
| CVE-2026-8024 | CRITICAL | 9.8 | 0.6% | Jun 18, 2026 | A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoor... |
| CVE-2026-56012 | HIGH | 8.5 | 0.2% | Jun 18, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Medi... |
| CVE-2026-56009 | MEDIUM | 5.9 | 0.1% | Jun 18, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricksable for Bri... |
| CVE-2026-56007 | MEDIUM | 5.9 | 0.1% | Jun 18, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Prod... |
| CVE-2026-54419 | CRITICAL | 9.8 | 0.6% | Jun 18, 2026 | claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1... |
| CVE-2026-54224 | HIGH | 7.1 | 0.3% | Jun 18, 2026 | UBB.threads is vulnerable to Denial of Service (DoS). By sending multiple concurrent requests to view any user profile o... |
| CVE-2026-54223 | HIGH | 8.6 | 0.6% | Jun 18, 2026 | UBB.threads is vulnerable to Path traversal, allowing attackers with privilege to edit templates to read and write any f... |
| CVE-2026-54222 | HIGH | 8.6 | 0.3% | Jun 18, 2026 | UBB.threads is vulnerable to Blind SQL Injection, allowing attackers with access to the Members in Control Panel to inte... |
| CVE-2026-54221 | MEDIUM | 5.1 | 0.3% | Jun 18, 2026 | UBB.threads is vulnerable to Reflected XSS. The application improperly handles user input in certain requests, enabling ... |
| CVE-2026-54220 | HIGH | 8.6 | 0.2% | Jun 18, 2026 | uBB.threads is vulnerable to a Cross-Site Request Forgery (CSRF) due to a lack of protective mechanisms. This allows an ... |
| CVE-2026-54219 | MEDIUM | 5.1 | 0.3% | Jun 18, 2026 | UBB.threads is vulnerable to Stored XSS via user posts and user profile fields. The application fails to properly saniti... |
| CVE-2026-50141 | HIGH | 7.1 | 0.2% | Jun 18, 2026 | Woodpecker is a CI/CD engine. Starting in version 3.0.0 and prior to version 3.14.1, a vulnerability in Woodpecker CI's ... |
| CVE-2026-44942 | MEDIUM | 6.5 | 0.3% | Jun 18, 2026 | A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series... |
| CVE-2026-42490 | MEDIUM | 6.5 | 0.2% | Jun 18, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-42489 | MEDIUM | 5.3 | 0.1% | Jun 18, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-42488 | HIGH | 8.1 | 0.4% | Jun 18, 2026 | Some shadow paging errors paths will switch the page-tables without updating the currently running vCPU reference. This... |
| CVE-2026-42487 | HIGH | 7.9 | 0.1% | Jun 18, 2026 | HVM guest I/O port accesses are subject to either emulation or at least translation. Translations are managed by the de... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now