2026 CVE Vulnerabilities
60,340 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56007 | MEDIUM | 5.9 | 0.1% | Jun 18, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Prod... |
| CVE-2026-54419 | CRITICAL | 9.8 | 0.6% | Jun 18, 2026 | claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1... |
| CVE-2026-54224 | HIGH | 7.1 | 0.3% | Jun 18, 2026 | UBB.threads is vulnerable to Denial of Service (DoS). By sending multiple concurrent requests to view any user profile o... |
| CVE-2026-54223 | HIGH | 8.6 | 0.6% | Jun 18, 2026 | UBB.threads is vulnerable to Path traversal, allowing attackers with privilege to edit templates to read and write any f... |
| CVE-2026-54222 | HIGH | 8.6 | 0.3% | Jun 18, 2026 | UBB.threads is vulnerable to Blind SQL Injection, allowing attackers with access to the Members in Control Panel to inte... |
| CVE-2026-54221 | MEDIUM | 5.1 | 0.3% | Jun 18, 2026 | UBB.threads is vulnerable to Reflected XSS. The application improperly handles user input in certain requests, enabling ... |
| CVE-2026-54220 | HIGH | 8.6 | 0.2% | Jun 18, 2026 | uBB.threads is vulnerable to a Cross-Site Request Forgery (CSRF) due to a lack of protective mechanisms. This allows an ... |
| CVE-2026-54219 | MEDIUM | 5.1 | 0.3% | Jun 18, 2026 | UBB.threads is vulnerable to Stored XSS via user posts and user profile fields. The application fails to properly saniti... |
| CVE-2026-50141 | HIGH | 7.1 | 0.2% | Jun 18, 2026 | Woodpecker is a CI/CD engine. Starting in version 3.0.0 and prior to version 3.14.1, a vulnerability in Woodpecker CI's ... |
| CVE-2026-44942 | MEDIUM | 6.5 | 0.3% | Jun 18, 2026 | A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series... |
| CVE-2026-42490 | MEDIUM | 6.5 | 0.2% | Jun 18, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-42489 | MEDIUM | 5.3 | 0.1% | Jun 18, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-42488 | HIGH | 8.1 | 0.4% | Jun 18, 2026 | Some shadow paging errors paths will switch the page-tables without updating the currently running vCPU reference. This... |
| CVE-2026-42487 | HIGH | 7.9 | 0.1% | Jun 18, 2026 | HVM guest I/O port accesses are subject to either emulation or at least translation. Translations are managed by the de... |
| CVE-2026-40457 | LOW | 2.1 | 0.3% | Jun 18, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in LMS (LAN Management System) before commit 9c5651b in the ... |
| CVE-2026-40456 | HIGH | 8.6 | 0.9% | Jun 18, 2026 | An OS Command Injection vulnerability exists in LMS (LAN Management System) before commit 9fcb4de due to an IP address p... |
| CVE-2026-40455 | HIGH | 8.6 | 0.2% | Jun 18, 2026 | An SQL Injection vulnerability exists in LMS (LAN Management System) before commit 4cb30a7 within the "tarifflist.php" m... |
| CVE-2026-12539 | MEDIUM | 5.7 | 0.1% | Jun 18, 2026 | Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-appl... |
| CVE-2026-12527 | MEDIUM | 6 | 0.2% | Jun 18, 2026 | A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V3... |
| CVE-2026-12039 | MEDIUM | 5.7 | 0.1% | Jun 18, 2026 | Docker Sandboxes (sbx) enforces an HTTP/S-only egress allowlist but does not apply it to DNS resolution: the per-network... |
| CVE-2026-11958 | HIGH | 7.3 | 0.1% | Jun 18, 2026 | Local privilege escalation by loading DLLs from a shared temporary directory in ANSSI’s DFIR-ORC, versions 10.2.7 and pr... |
| CVE-2026-11719 | HIGH | 8.1 | 0.1% | Jun 18, 2026 | An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement... |
| CVE-2026-11718 | CRITICAL | 9.1 | 0.2% | Jun 18, 2026 | An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googl... |
| CVE-2026-11717 | CRITICAL | 9.1 | 0.2% | Jun 18, 2026 | An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googl... |
| CVE-2026-8811 | HIGH | 7.1 | 0.3% | Jun 18, 2026 | SEPPmail versions before 15.0.5 allow improper handling of attachment filenames during encrypted PDF generation. An atta... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now