2026 CVE Vulnerabilities
61,069 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45357 | HIGH | 7.5 | 0.4% | Jun 17, 2026 | LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below,... |
| CVE-2026-44646 | MEDIUM | 5.3 | 0.3% | Jun 17, 2026 | LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below,... |
| CVE-2026-44645 | MEDIUM | 6.5 | 0.3% | Jun 17, 2026 | LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below,... |
| CVE-2026-44644 | MEDIUM | 6.1 | 0.2% | Jun 17, 2026 | LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. Versions 10.25.7 and below are... |
| CVE-2026-12568 | MEDIUM | 6.5 | 0.3% | Jun 17, 2026 | The postman_download module uses the workspace name field from the Postman API to construct the local directory path wit... |
| CVE-2026-12567 | LOW | 2.2 | 0.1% | Jun 17, 2026 | The github_workflows module constructs local directory paths from user-controlled repository names without validating fo... |
| CVE-2026-12566 | LOW | 3.1 | 0.2% | Jun 17, 2026 | The docker_pull module uses the realm parameter from a Docker registry's WWW-Authenticate response header as the authent... |
| CVE-2026-12565 | MEDIUM | 5.3 | 0.2% | Jun 17, 2026 | The unarchive internal module's archive extraction commands perform no code-level validation on extracted file paths, re... |
| CVE-2026-8050 | HIGH | 7.5 | 0.3% | Jun 17, 2026 | In SignalRGB versions prior to 1.3.7.0, seven of the thirteen IOCTL handlers dereference the SystemBuffer pointer withou... |
| CVE-2026-8049 | MEDIUM | 5.3 | 0.1% | Jun 17, 2026 | In SignalRGB versions prior to 1.3.7.0, the \\.\SignalIo device object is created without an explicit SDDL security desc... |
| CVE-2026-54386 | MEDIUM | 6.1 | 0.2% | Jun 17, 2026 | marimo before 0.23.9 contains a reflected cross-site scripting vulnerability in the notebook page that allows unauthenti... |
| CVE-2026-50200 | HIGH | 7.5 | 0.2% | Jun 17, 2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati... |
| CVE-2026-50196 | HIGH | 7.5 | 0.3% | Jun 17, 2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati... |
| CVE-2026-50194 | HIGH | 8.2 | 0.2% | Jun 17, 2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati... |
| CVE-2026-48997 | HIGH | 7.1 | 0.7% | Jun 17, 2026 | e107 is a content management system (CMS). Versions 2.3.5 and earlier contain a command injection vulnerability in the ... |
| CVE-2026-48991 | MEDIUM | 5.5 | 0.1% | Jun 17, 2026 | XianYuLauncher is a Minecraft Java Edition launcher. In versions prior to 1.5.5, sensitive authentication artifacts coul... |
| CVE-2026-48990 | MEDIUM | 5.3 | 0.2% | Jun 17, 2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar... |
| CVE-2026-48989 | HIGH | 8.9 | 0.4% | Jun 17, 2026 | Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP m... |
| CVE-2026-48820 | MEDIUM | 6.3 | 0.3% | Jun 17, 2026 | CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1... |
| CVE-2026-12530 | HIGH | 8.4 | 0.3% | Jun 17, 2026 | Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK vers... |
| CVE-2026-49133 | HIGH | 7.1 | 0.3% | Jun 17, 2026 | Typemill before 2.24.0 contains a path traversal vulnerability that allows authenticated attackers with Author-level pri... |
| CVE-2026-48988 | MEDIUM | 5.3 | 0.3% | Jun 17, 2026 | markdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: ... |
| CVE-2026-48979 | HIGH | 7.5 | 0.3% | Jun 17, 2026 | PHP Standard Library (PSL) is set of APIs covering async, collections, networking, I/O, cryptography, terminal UI, etc. ... |
| CVE-2026-48821 | MEDIUM | 5.8 | 0.1% | Jun 17, 2026 | Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a DOM-based Cross-Site Scripting (XSS) vuln... |
| CVE-2026-55202 | HIGH | 8.8 | 0.3% | Jun 17, 2026 | Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection,... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now