2026 CVE Vulnerabilities
61,161 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12515 | MEDIUM | 4.3 | 0.2% | Jun 17, 2026 | A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization chec... |
| CVE-2026-12151 | HIGH | 7.5 | 0.8% | Jun 17, 2026 | Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but d... |
| CVE-2026-55748 | MEDIUM | 6 | 0.2% | Jun 17, 2026 | OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name ... |
| CVE-2026-55743 | CRITICAL | 9.6 | 0.7% | Jun 17, 2026 | The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised sec... |
| CVE-2026-54812 | CRITICAL | 9.3 | 0.3% | Jun 17, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Mot... |
| CVE-2026-54810 | HIGH | 7.5 | 0.2% | Jun 17, 2026 | Missing Authorization vulnerability in Nexi Payments Nexi XPay allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2026-54415 | HIGH | 8.6 | 0.3% | Jun 17, 2026 | Missing Authorization in the server management routes (routes/admin.php) in Azuriom Azuriom CMS before 1.2.11 on all pla... |
| CVE-2026-49502 | HIGH | 8.1 | 0.2% | Jun 17, 2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthentic... |
| CVE-2026-48142 | MEDIUM | 6.3 | 0.7% | Jun 17, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or p... |
| CVE-2026-48117 | MEDIUM | 6.8 | 0.2% | Jun 17, 2026 | DroneAware is a drone detection platform. The centralized DroneAware server backing droneaware.io was vulnerable to an a... |
| CVE-2026-47103 | CRITICAL | 9.8 | 1.3% | Jun 17, 2026 | Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to ... |
| CVE-2026-42530 | CRITICAL | 9.2 | 3.2% | Jun 17, 2026 | NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the ... |
| CVE-2026-42055 | HIGH | 8.1 | 6.5% | Jun 17, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. ... |
| CVE-2026-40641 | MEDIUM | 4.8 | 0.1% | Jun 17, 2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Use of a Broken or Risky Cryptographic Algorithm vuln... |
| CVE-2026-35162 | MEDIUM | 6.5 | 0.2% | Jun 17, 2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileg... |
| CVE-2026-35067 | HIGH | 8 | 0.1% | Jun 17, 2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileg... |
| CVE-2026-35066 | HIGH | 7.1 | 0.2% | Jun 17, 2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileg... |
| CVE-2026-35065 | HIGH | 8.8 | 0.3% | Jun 17, 2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) a Missing Authentication for Critical Function vulnerabi... |
| CVE-2026-32804 | HIGH | 8.1 | 0.2% | Jun 17, 2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Authentication vulnerability. An unauthentic... |
| CVE-2026-22283 | HIGH | 7.5 | 0.2% | Jun 17, 2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Inclusion of Functionality from Untrusted Control Sph... |
| CVE-2026-12528 | MEDIUM | 5.4 | 0.2% | Jun 17, 2026 | A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Acce... |
| CVE-2026-11311 | MEDIUM | 6.5 | 0.6% | Jun 17, 2026 | When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX... |
| CVE-2026-10850 | MEDIUM | 5.4 | 0.2% | Jun 17, 2026 | Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when cre... |
| CVE-2026-9591 | MEDIUM | 6.9 | 0.2% | Jun 17, 2026 | Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthent... |
| CVE-2026-55738 | HIGH | 8.8 | 0.6% | Jun 17, 2026 | A stack-based buffer overflow exists in the raw_to_header function in src/microtar.c in rxi microtar 0.1.0. The function... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now