2026 CVE Vulnerabilities
61,161 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54819 | CRITICAL | 9.3 | 0.2% | Jun 17, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listd... |
| CVE-2026-54818 | HIGH | 8.5 | 0.2% | Jun 17, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs Slimsta... |
| CVE-2026-54817 | MEDIUM | 6.5 | 0.3% | Jun 17, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recover... |
| CVE-2026-54816 | HIGH | 7.5 | 0.3% | Jun 17, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Monetizemore Advanced Ads allows Remote Code ... |
| CVE-2026-54815 | CRITICAL | 9.3 | 0.2% | Jun 17, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shi... |
| CVE-2026-54814 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-54813 | HIGH | 8.5 | 0.2% | Jun 17, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force S... |
| CVE-2026-54809 | CRITICAL | 9.3 | 0.2% | Jun 17, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme GIFT4U ... |
| CVE-2026-54808 | CRITICAL | 9.3 | 0.3% | Jun 17, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Trave... |
| CVE-2026-54417 | HIGH | 8.7 | 0.4% | Jun 17, 2026 | An integer overflow in the mtar_next function in src/microtar.c in rxi microtar 0.1.0 allows a remote attacker to cause ... |
| CVE-2026-54193 | HIGH | 7.7 | 0.3% | Jun 17, 2026 | Contributor Arbitrary File Deletion in Fusion Builder <= 3.15.4 versions. |
| CVE-2026-52716 | MEDIUM | 6.5 | 0.4% | Jun 17, 2026 | Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions. |
| CVE-2026-52707 | HIGH | 8.1 | 0.4% | Jun 17, 2026 | Unauthenticated Local File Inclusion in Kastell <= 2.0 versions. |
| CVE-2026-49268 | CRITICAL | 9.1 | 0.5% | Jun 17, 2026 | A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm c... |
| CVE-2026-49108 | CRITICAL | 9.8 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Moderno < 1.43 versions. |
| CVE-2026-40757 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Château <= 1.2.1 versions. |
| CVE-2026-40756 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Zoya <= 1.4 versions. |
| CVE-2026-40752 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Manufaktur Solutions <= 1.1.1 versions. |
| CVE-2026-40738 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Eldon <= 1.4.1 versions. |
| CVE-2026-40733 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in ShiftUp <= 1.3 versions. |
| CVE-2026-40720 | HIGH | 7.1 | 0.2% | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in Royal Elementor Addons Pro < 1.7.1041 versions. |
| CVE-2026-39590 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions. |
| CVE-2026-39576 | HIGH | 8.1 | 0.4% | Jun 17, 2026 | Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions. |
| CVE-2026-39560 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions. |
| CVE-2026-39559 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated Local File Inclusion in Uppercase < 1.2.2 versions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now