2026 CVE Vulnerabilities
61,030 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49345 | MEDIUM | 5.3 | 0.5% | Jun 19, 2026 | Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, ... |
| CVE-2026-49344 | HIGH | 7.1 | 0.3% | Jun 19, 2026 | Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, ... |
| CVE-2026-49342 | MEDIUM | 5.3 | 0.3% | Jun 19, 2026 | YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache ... |
| CVE-2026-48787 | HIGH | 7.4 | 0.5% | Jun 19, 2026 | gin-vue-admin is an AI-assisted basic development platform. In version 2.9.1, an authenticated attacker with access to t... |
| CVE-2026-48774 | HIGH | 7.5 | 0.4% | Jun 19, 2026 | ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 3.0.0 through 3.0.8, ProxySQL's GenAI/MC... |
| CVE-2026-48773 | CRITICAL | 9.8 | 0.7% | Jun 19, 2026 | ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-authenticat... |
| CVE-2026-48772 | CRITICAL | 10 | 0.2% | Jun 19, 2026 | ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL ... |
| CVE-2026-48715 | HIGH | 8.8 | 0.2% | Jun 19, 2026 | radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the `radvdump` utility shipped with radvd contai... |
| CVE-2026-48089 | HIGH | 7.1 | 0.2% | Jun 19, 2026 | DevGuard provides vulnerability management for the full software supply chain. Prior to 1.4.2, on a DevGuard API instanc... |
| CVE-2026-9375 | — | — | 0.3% | Jun 19, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-49340 | HIGH | 8.1 | 0.3% | Jun 19, 2026 | gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, a logic e... |
| CVE-2026-49339 | HIGH | 7.1 | 0.3% | Jun 19, 2026 | gonic is a music streaming server / free-software subsonic server API implementation. The maintainer's fix in commit `6... |
| CVE-2026-49338 | HIGH | 7.1 | 0.2% | Jun 19, 2026 | gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, the Subso... |
| CVE-2026-49336 | MEDIUM | 5.5 | 0.7% | Jun 19, 2026 | @microsoft/kiota-http-fetchlibrary provides TypeScript libraries for Kiota-generated API clients. In versions 1.0.0-prev... |
| CVE-2026-49293 | HIGH | 7.5 | 0.3% | Jun 19, 2026 | js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. Versions up to and including 1.1.0 pa... |
| CVE-2026-49291 | HIGH | 8.1 | 0.3% | Jun 19, 2026 | mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpo... |
| CVE-2026-49288 | MEDIUM | 4.3 | 0.2% | Jun 19, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, an authenticated Con... |
| CVE-2026-27878 | MEDIUM | 6.5 | 0.2% | Jun 19, 2026 | A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive... |
| CVE-2026-12726 | MEDIUM | 6.3 | 0.2% | Jun 19, 2026 | A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull_request webhooks, the controller sto... |
| CVE-2026-12238 | MEDIUM | 5.3 | 0.2% | Jun 19, 2026 | The WP Go Maps – Most Popular Map Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up t... |
| CVE-2026-49359 | MEDIUM | 6.5 | 0.2% | Jun 19, 2026 | PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/... |
| CVE-2026-49290 | HIGH | 7.6 | 0.6% | Jun 19, 2026 | Slopsmith is a self-contained web application for browsing, playing, and practicing Rocksmith 2014 Custom DLC (CDLC). Pr... |
| CVE-2026-49287 | HIGH | 7.4 | 0.3% | Jun 19, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, the fix for CVE-2026... |
| CVE-2026-49286 | HIGH | 8.1 | 0.6% | Jun 19, 2026 | PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/... |
| CVE-2026-49271 | MEDIUM | 6.5 | 0.2% | Jun 19, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder valid... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now