2026 CVE Vulnerabilities
60,340 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54387 | CRITICAL | 9.3 | 0.4% | Jun 17, 2026 | Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile conflicting Content-Length and Transfer-Encoding: ... |
| CVE-2026-50107 | HIGH | 8.6 | 0.5% | Jun 17, 2026 | When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulnerabilit... |
| CVE-2026-48823 | MEDIUM | 4.8 | 0.1% | Jun 17, 2026 | Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnera... |
| CVE-2026-48822 | MEDIUM | 5.8 | 0.1% | Jun 17, 2026 | Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnera... |
| CVE-2026-48817 | MEDIUM | 5.3 | 0.2% | Jun 17, 2026 | Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint... |
| CVE-2026-48814 | CRITICAL | 9.1 | 0.3% | Jun 17, 2026 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows un... |
| CVE-2026-32682 | HIGH | 7.1 | 0.3% | Jun 17, 2026 | When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or... |
| CVE-2026-12529 | HIGH | 7.3 | 0.3% | Jun 17, 2026 | A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1... |
| CVE-2026-11407 | HIGH | 8.6 | 0.6% | Jun 17, 2026 | Pimcore CMS/DXP version 12.3.8 contains a sandbox bypass vulnerability that allows authenticated administrative attacker... |
| CVE-2026-10741 | MEDIUM | 4.9 | 0.3% | Jun 17, 2026 | Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configur... |
| CVE-2026-10696 | HIGH | 7.5 | 0.3% | Jun 17, 2026 | Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier all... |
| CVE-2026-55198 | HIGH | 7.1 | 0.3% | Jun 17, 2026 | Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows a... |
| CVE-2026-55197 | HIGH | 7.1 | 0.3% | Jun 17, 2026 | Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows aut... |
| CVE-2026-55196 | CRITICAL | 9.1 | 0.6% | Jun 17, 2026 | Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allo... |
| CVE-2026-53871 | HIGH | 8.6 | 0.4% | Jun 17, 2026 | Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that ac... |
| CVE-2026-53870 | MEDIUM | 6.8 | 0.1% | Jun 17, 2026 | Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mod... |
| CVE-2026-53869 | HIGH | 8.7 | 0.6% | Jun 17, 2026 | Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to... |
| CVE-2026-48818 | HIGH | 7.5 | 0.4% | Jun 17, 2026 | Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable t... |
| CVE-2026-9697 | HIGH | 7.4 | 0.5% | Jun 17, 2026 | Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or s... |
| CVE-2026-9679 | MEDIUM | 5.9 | 0.3% | Jun 17, 2026 | Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences... |
| CVE-2026-9678 | MEDIUM | 5.9 | 0.3% | Jun 17, 2026 | Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control he... |
| CVE-2026-7300 | MEDIUM | 6.5 | 0.3% | Jun 17, 2026 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Web In... |
| CVE-2026-6734 | HIGH | 8.8 | 0.3% | Jun 17, 2026 | Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying t... |
| CVE-2026-6733 | LOW | 3.7 | 0.2% | Jun 17, 2026 | Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-con... |
| CVE-2026-53805 | CRITICAL | 9.8 | 0.7% | Jun 17, 2026 | NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inf... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now