2026 CVE Vulnerabilities
61,030 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49871 | CRITICAL | 9.3 | 0.3% | Jun 19, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows... |
| CVE-2026-49357 | HIGH | 8.8 | 0.3% | Jun 19, 2026 | Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly o... |
| CVE-2026-49231 | MEDIUM | 5.4 | 0.4% | Jun 19, 2026 | Authentication Bypass by Spoofing vulnerability in opa plugin. An attacker could relay spoofed identity headers to upst... |
| CVE-2026-49230 | CRITICAL | 9.1 | 0.2% | Jun 19, 2026 | Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default confi... |
| CVE-2026-48895 | HIGH | 7.2 | 0.4% | Jun 19, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some ... |
| CVE-2026-48141 | HIGH | 7.5 | 0.2% | Jun 19, 2026 | There is a memory leak in NI grpc-device BeginSidebandStream that may result in denial of service due to memory exhausti... |
| CVE-2026-48140 | HIGH | 7.1 | 0.3% | Jun 19, 2026 | There is an unchecked enum cast vulnerability in NI grpc-device BeginSidebandStream that may allow an attacker to trigge... |
| CVE-2026-48139 | HIGH | 8.7 | 0.3% | Jun 19, 2026 | There is a NULL pointer dereference vulnerability in NI grpc-device in the data moniker service that may allow an attack... |
| CVE-2026-48138 | HIGH | 8.7 | 0.3% | Jun 19, 2026 | There is an out-of-bounds read vulnerability in the NI grpc-device streaming API due to a missing bounds check that may ... |
| CVE-2026-48137 | CRITICAL | 9.8 | 0.5% | Jun 19, 2026 | There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an a... |
| CVE-2026-47341 | MEDIUM | 6.5 | 0.4% | Jun 19, 2026 | Authentication Bypass by Capture-replay vulnerability in Apache APISIX. Attacker can benefit from certain configuration... |
| CVE-2026-47339 | HIGH | 8.1 | 0.3% | Jun 19, 2026 | Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under defaul... |
| CVE-2026-44915 | MEDIUM | 6.1 | 0.4% | Jun 19, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The default configuration of cas-au... |
| CVE-2026-44087 | CRITICAL | 9.1 | 0.2% | Jun 19, 2026 | Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect plugin under default ... |
| CVE-2026-44046 | MEDIUM | 5.8 | 0.3% | Jun 19, 2026 | Use of Less Trusted Source vulnerability in Apache APISIX. Attacker can take advantage of wolf-rbac plugin under defaul... |
| CVE-2026-39999 | CRITICAL | 9.1 | 0.4% | Jun 19, 2026 | Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication cap... |
| CVE-2026-39998 | HIGH | 8.8 | 0.4% | Jun 19, 2026 | Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in f... |
| CVE-2026-12104 | HIGH | 8.6 | 1.1% | Jun 19, 2026 | OS command injection in the environment and tunnel configuration functionality in SIMA GmbH Bondix through version 1.25.... |
| CVE-2026-56142 | HIGH | 8.8 | 0.4% | Jun 19, 2026 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privileg... |
| CVE-2026-56141 | CRITICAL | 9.8 | 0.4% | Jun 19, 2026 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account ... |
| CVE-2026-53915 | HIGH | 8.8 | 0.2% | Jun 19, 2026 | In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration |
| CVE-2026-50242 | CRITICAL | 9.8 | 0.4% | Jun 19, 2026 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authenti... |
| CVE-2026-44939 | CRITICAL | 9.4 | 1.1% | Jun 19, 2026 | A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clus... |
| CVE-2026-12706 | MEDIUM | 6.5 | 0.2% | Jun 19, 2026 | A use-after-free vulnerability was found in FFmpeg's RASC video decoder. The decode_move() function initializes a read p... |
| CVE-2026-11941 | MEDIUM | 5.6 | 0.2% | Jun 19, 2026 | Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions. The “... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now