2026 CVE Vulnerabilities
61,049 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49454 | CRITICAL | 9.1 | 0.1% | Jun 18, 2026 | Relyra is a strict-by-default SAML 2.0 Service Provider library for Elixir and Phoenix. Versions 1.0.0 and 1.1.0 accept ... |
| CVE-2026-49257 | CRITICAL | 10 | 0.5% | Jun 18, 2026 | mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. In versions 3.0.1 and... |
| CVE-2026-49252 | CRITICAL | 9.9 | 0.3% | Jun 18, 2026 | deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. Vers... |
| CVE-2026-49248 | HIGH | 8.3 | 0.4% | Jun 18, 2026 | OneDev is a Git server with CI/CD, kanban, and packages. In versions 15.0.6 and below, TarUtils.untar() creates symbolic... |
| CVE-2026-46699 | HIGH | 7.6 | 0.2% | Jun 18, 2026 | conda-smithy is a tool for combining a conda recipe with configurations to build using freely hosted CI services into a ... |
| CVE-2026-45696 | MEDIUM | 6.5 | 0.3% | Jun 18, 2026 | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in... |
| CVE-2026-44663 | HIGH | 7.1 | 0.2% | Jun 18, 2026 | OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in... |
| CVE-2026-43994 | CRITICAL | 9.8 | 0.4% | Jun 18, 2026 | Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.10.0 contain a stack buffer ove... |
| CVE-2026-56099 | MEDIUM | 5.3 | 0.4% | Jun 18, 2026 | OpenBSD before commit 6a23123 (2026-06-18) contains an out-of-bounds read vulnerability in the mpls_do_error function wi... |
| CVE-2026-48983 | MEDIUM | 5.8 | 0.1% | Jun 18, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, a symlink... |
| CVE-2026-48982 | MEDIUM | 5.8 | 0.1% | Jun 18, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, when upda... |
| CVE-2026-48981 | MEDIUM | 6.7 | 0.1% | Jun 18, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, pam_usb c... |
| CVE-2026-48980 | MEDIUM | 6.3 | 0.1% | Jun 18, 2026 | pam_usb provides hardware authentication for Linux using removable media. In versions prior to 0.9.2, getenv() environm... |
| CVE-2026-48716 | HIGH | 8.7 | 0.3% | Jun 18, 2026 | nanobot is a personal AI assistant. In versions 0.1.5.post3 and prior, the WhatsApp bridge in bridge/src/whatsapp.ts con... |
| CVE-2026-47847 | MEDIUM | 5.3 | 0.2% | Jun 18, 2026 | Bitnami MariaDB Galera container images and Helm chart are affected by a hardcoded default credential vulnerability in t... |
| CVE-2026-47846 | CRITICAL | 9.8 | 0.3% | Jun 18, 2026 | Bitnami Cassandra container images are affected by a retained default superuser vulnerability. When a custom administrat... |
| CVE-2026-43915 | MEDIUM | 5.4 | 0.1% | Jun 18, 2026 | Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.11.0 contain a stored cross-sit... |
| CVE-2026-2842 | — | — | — | Jun 18, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2026-25865 | HIGH | 8.5 | 0.1% | Jun 18, 2026 | Punto Switcher through 4.5.0.583 contains an unquoted search path element vulnerability that allows local attackers to e... |
| CVE-2026-9692 | MEDIUM | 5.3 | 0.3% | Jun 18, 2026 | Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The default session id ... |
| CVE-2026-55392 | MEDIUM | 6.7 | 0.1% | Jun 18, 2026 | NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size ... |
| CVE-2026-48937 | HIGH | 7.5 | 0.5% | Jun 18, 2026 | A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This v... |
| CVE-2026-47833 | MEDIUM | 6.9 | 0.1% | Jun 18, 2026 | setupBpmLogs follows symlink for bpm.log open and chown — container-to-host privilege escalation via /etc/shadow. A comp... |
| CVE-2026-12390 | HIGH | 7.8 | 0.1% | Jun 18, 2026 | In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by an attacker using spe... |
| CVE-2026-54390 | CRITICAL | 9.8 | 0.3% | Jun 18, 2026 | JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticate... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now