2026 CVE Vulnerabilities
61,122 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35162 | MEDIUM | 6.5 | 0.2% | Jun 17, 2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileg... |
| CVE-2026-35067 | HIGH | 8 | 0.1% | Jun 17, 2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileg... |
| CVE-2026-35066 | HIGH | 7.1 | 0.2% | Jun 17, 2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileg... |
| CVE-2026-35065 | HIGH | 8.8 | 0.3% | Jun 17, 2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Missing Authentication for Critical Function vulnerabi... |
| CVE-2026-32804 | HIGH | 8.1 | 0.2% | Jun 17, 2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthentic... |
| CVE-2026-22283 | HIGH | 7.5 | 0.2% | Jun 17, 2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Inclusion of Functionality from Untrusted Control Sph... |
| CVE-2026-12528 | MEDIUM | 5.4 | 0.2% | Jun 17, 2026 | A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Acce... |
| CVE-2026-11311 | MEDIUM | 6.5 | 0.6% | Jun 17, 2026 | When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX... |
| CVE-2026-10850 | MEDIUM | 5.4 | 0.2% | Jun 17, 2026 | Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when cre... |
| CVE-2026-9591 | MEDIUM | 6.9 | 0.2% | Jun 17, 2026 | Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthent... |
| CVE-2026-55738 | HIGH | 8.8 | 0.6% | Jun 17, 2026 | A stack-based buffer overflow exists in the raw_to_header function in src/microtar.c in rxi microtar 0.1.0. The function... |
| CVE-2026-54819 | CRITICAL | 9.3 | 0.2% | Jun 17, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listd... |
| CVE-2026-54818 | HIGH | 8.5 | 0.2% | Jun 17, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs Slimsta... |
| CVE-2026-54817 | MEDIUM | 6.5 | 0.3% | Jun 17, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recover... |
| CVE-2026-54816 | HIGH | 7.5 | 0.3% | Jun 17, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Monetizemore Advanced Ads allows Remote Code ... |
| CVE-2026-54815 | CRITICAL | 9.3 | 0.2% | Jun 17, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shi... |
| CVE-2026-54814 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-54813 | HIGH | 8.5 | 0.2% | Jun 17, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force S... |
| CVE-2026-54809 | CRITICAL | 9.3 | 0.2% | Jun 17, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme GIFT4U ... |
| CVE-2026-54808 | CRITICAL | 9.3 | 0.3% | Jun 17, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Trave... |
| CVE-2026-54417 | HIGH | 8.7 | 0.4% | Jun 17, 2026 | An integer overflow in the mtar_next function in src/microtar.c in rxi microtar 0.1.0 allows a remote attacker to cause ... |
| CVE-2026-54193 | HIGH | 7.7 | 0.3% | Jun 17, 2026 | Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions. |
| CVE-2026-52716 | MEDIUM | 6.5 | 0.4% | Jun 17, 2026 | Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions. |
| CVE-2026-52707 | HIGH | 8.1 | 0.4% | Jun 17, 2026 | Unauthenticated Local File Inclusion in Kastell <= 2.0 versions. |
| CVE-2026-49268 | CRITICAL | 9.1 | 0.5% | Jun 17, 2026 | A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm c... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now