2026 CVE Vulnerabilities
61,018 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12804 | MEDIUM | 4.3 | 0.3% | Jun 21, 2026 | A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-p... |
| CVE-2026-56412 | MEDIUM | 5.9 | 0.1% | Jun 21, 2026 | libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking ... |
| CVE-2026-56411 | MEDIUM | 6.9 | 0.1% | Jun 21, 2026 | xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations. |
| CVE-2026-56410 | MEDIUM | 6.9 | 0.1% | Jun 21, 2026 | xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId. |
| CVE-2026-56409 | MEDIUM | 6.5 | 0.1% | Jun 21, 2026 | xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used. |
| CVE-2026-56408 | MEDIUM | 6.9 | 0.1% | Jun 21, 2026 | libexpat before 2.8.2 has an integer overflow in copyString. |
| CVE-2026-56407 | MEDIUM | 6.9 | 0.1% | Jun 21, 2026 | libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen. |
| CVE-2026-56406 | MEDIUM | 6.9 | 0.1% | Jun 21, 2026 | libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse... |
| CVE-2026-56405 | MEDIUM | 6.9 | 0.1% | Jun 21, 2026 | libexpat before 2.8.2 has an integer overflow in getAttributeId. |
| CVE-2026-56404 | MEDIUM | 6.9 | 0.1% | Jun 21, 2026 | libexpat before 2.8.2 has an integer overflow in addBinding. |
| CVE-2026-56403 | MEDIUM | 6.9 | 0.1% | Jun 21, 2026 | libexpat before 2.8.2 has an integer overflow in storeAtts. |
| CVE-2026-56397 | CRITICAL | 9.6 | 0.4% | Jun 21, 2026 | SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious... |
| CVE-2026-56396 | HIGH | 8.8 | 0.3% | Jun 21, 2026 | phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that... |
| CVE-2026-56395 | — | — | 0.7% | Jun 21, 2026 | Rejected reason: This record is a duplicate; use CVE-2026-56397 instead. |
| CVE-2026-56394 | HIGH | 7.1 | 0.3% | Jun 21, 2026 | Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the ex... |
| CVE-2026-56393 | MEDIUM | 4.8 | 0.2% | Jun 21, 2026 | Craft CMS 4.x (>= 4.0.0-RC1, < 4.17.0-beta.1) and 5.x (>= 5.0.0-RC1, < 5.9.0-beta.1) contain multiple stored cross-site ... |
| CVE-2026-56385 | MEDIUM | 5.3 | 0.2% | Jun 21, 2026 | Craft CMS versions >= 5.0.0-RC1, <= 5.9.13 and >= 4.0.0-RC1, <= 4.17.7 contain an authorization bypass in the assets/pre... |
| CVE-2026-56384 | MEDIUM | 5.3 | 0.2% | Jun 21, 2026 | Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Control Panel user with... |
| CVE-2026-56383 | MEDIUM | 4.8 | 0.2% | Jun 21, 2026 | Craft CMS contains a stored cross-site scripting (XSS) vulnerability in the editableTable.twig component when using the ... |
| CVE-2026-56382 | HIGH | 8.6 | 0.5% | Jun 21, 2026 | Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerability ... |
| CVE-2026-56381 | MEDIUM | 4.8 | 0.1% | Jun 21, 2026 | Craft CMS from version 5.0.0-RC1 contains a stored cross-site scripting vulnerability in the User Permissions page where... |
| CVE-2026-56378 | HIGH | 8.2 | 0.2% | Jun 21, 2026 | ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage... |
| CVE-2026-56367 | CRITICAL | 9.1 | 0.2% | Jun 21, 2026 | ImageMagick before 7.1.2-15 and 6.9.x before 6.9.13-40 contains an integer overflow in the PSB (PSD v2) RLE decoding pat... |
| CVE-2026-56316 | MEDIUM | 6.9 | 0.2% | Jun 21, 2026 | Cap-go before 12.128.2 contains an information disclosure vulnerability in the OPTIONS /build/upload/:jobId/* endpoint t... |
| CVE-2026-56299 | MEDIUM | 6.9 | 0.4% | Jun 21, 2026 | Capgo before 12.128.2 contains an authentication bypass vulnerability in the /build/upload/:jobId/* endpoint that allows... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now