2026 CVE Vulnerabilities
60,251 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40457 | LOW | 2.1 | 0.3% | Jun 18, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in LMS (LAN Management System) before commit 9c5651b in the ... |
| CVE-2026-40456 | HIGH | 8.6 | 0.9% | Jun 18, 2026 | An OS Command Injection vulnerability exists in LMS (LAN Management System) before commit 9fcb4de due to an IP address p... |
| CVE-2026-40455 | HIGH | 8.6 | 0.2% | Jun 18, 2026 | An SQL Injection vulnerability exists in LMS (LAN Management System) before commit 4cb30a7 within the "tarifflist.php" m... |
| CVE-2026-12539 | MEDIUM | 5.7 | 0.1% | Jun 18, 2026 | Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-appl... |
| CVE-2026-12527 | MEDIUM | 6 | 0.2% | Jun 18, 2026 | A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V3... |
| CVE-2026-12039 | MEDIUM | 5.7 | 0.1% | Jun 18, 2026 | Docker Sandboxes (sbx) enforces an HTTP/S-only egress allowlist but does not apply it to DNS resolution: the per-network... |
| CVE-2026-11958 | HIGH | 7.3 | 0.1% | Jun 18, 2026 | Local privilege escalation by loading DLLs from a shared temporary directory in ANSSI’s DFIR-ORC, versions 10.2.7 and pr... |
| CVE-2026-11719 | HIGH | 8.1 | 0.1% | Jun 18, 2026 | An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement... |
| CVE-2026-11718 | CRITICAL | 9.1 | 0.2% | Jun 18, 2026 | An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googl... |
| CVE-2026-11717 | CRITICAL | 9.1 | 0.2% | Jun 18, 2026 | An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googl... |
| CVE-2026-8811 | HIGH | 7.1 | 0.3% | Jun 18, 2026 | SEPPmail versions before 15.0.5 allow improper handling of attachment filenames during encrypted PDF generation. An atta... |
| CVE-2026-8039 | MEDIUM | 6.4 | 0.2% | Jun 18, 2026 | The Fancy Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'author' shortcode attr... |
| CVE-2026-50643 | MEDIUM | 5.1 | 0.1% | Jun 18, 2026 | 8cc is vulnerable to an Out‑of‑Bounds Read due to improper handling of #line directives and GNU linemarkers. The compile... |
| CVE-2026-2021 | MEDIUM | 6.4 | 0.2% | Jun 18, 2026 | The Slideshow Gallery LITE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'alwaysauto' shortc... |
| CVE-2026-9815 | MEDIUM | 6.5 | 0.2% | Jun 18, 2026 | The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenti... |
| CVE-2026-55746 | HIGH | 7.6 | 0.2% | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to stored Cross-Site Scripting in the Personal File Storage... |
| CVE-2026-55745 | MEDIUM | 5.4 | 0.1% | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage ... |
| CVE-2026-55744 | HIGH | 8.6 | 0.2% | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage ... |
| CVE-2026-55742 | CRITICAL | 9.6 | 0.2% | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights ... |
| CVE-2026-55741 | HIGH | 8.8 | 0.2% | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration configu... |
| CVE-2026-28573 | MEDIUM | 5.5 | 0.1% | Jun 18, 2026 | In AndroidManifest.xml, there is a possible persistent denial of service due to a missing permission check. This could l... |
| CVE-2026-12137 | MEDIUM | 6.1 | 0.2% | Jun 18, 2026 | The SysBasics Customize My Account for WooCommerce – Dashboard, Endpoints, Avatar & Menu Manager plugin for WordPress is... |
| CVE-2026-12136 | MEDIUM | 6.4 | 0.2% | Jun 18, 2026 | The Customize My Account For Woocommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sysb... |
| CVE-2026-12111 | MEDIUM | 4.3 | 0.3% | Jun 18, 2026 | The Appointment Booking Calendar plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to,... |
| CVE-2026-12102 | LOW | 2.7 | 0.3% | Jun 18, 2026 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now