2026 CVE Vulnerabilities
61,161 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49072 | MEDIUM | 6.5 | 0.3% | Jun 17, 2026 | Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions. |
| CVE-2026-49071 | MEDIUM | 6.5 | 0.3% | Jun 17, 2026 | Unauthenticated Broken Authentication in WooCommerce Dropshipping <= 5.2.4 versions. |
| CVE-2026-49058 | CRITICAL | 9.8 | 0.3% | Jun 17, 2026 | Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions. |
| CVE-2026-49057 | HIGH | 7.5 | 0.3% | Jun 17, 2026 | Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions. |
| CVE-2026-48967 | HIGH | 8.5 | 0.3% | Jun 17, 2026 | Subscriber SQL Injection in Geo Mashup <= 1.13.19 versions. |
| CVE-2026-48929 | HIGH | 7.5 | 0.7% | Jun 17, 2026 | Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthent... |
| CVE-2026-48875 | CRITICAL | 9.3 | 0.4% | Jun 17, 2026 | Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions. |
| CVE-2026-48869 | HIGH | 7.1 | 0.2% | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in Enfold <= 7.1.4 versions. |
| CVE-2026-48797 | CRITICAL | 9.3 | 0.3% | Jun 17, 2026 | Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, th... |
| CVE-2026-48788 | HIGH | 8.2 | 0.3% | Jun 17, 2026 | Remark42 is a self-hosted comment engine for blogs, articles, or any other place where readers can add comments. Version... |
| CVE-2026-48783 | MEDIUM | 4.8 | 0.2% | Jun 17, 2026 | Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accept... |
| CVE-2026-48782 | MEDIUM | 6.8 | 0.3% | Jun 17, 2026 | Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 t... |
| CVE-2026-48781 | CRITICAL | 9.9 | 0.2% | Jun 17, 2026 | Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an atta... |
| CVE-2026-48779 | HIGH | 7.5 | 0.8% | Jun 17, 2026 | ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, f... |
| CVE-2026-48745 | CRITICAL | 9.3 | 0.3% | Jun 17, 2026 | Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Tracca... |
| CVE-2026-48616 | CRITICAL | 9.3 | 0.3% | Jun 17, 2026 | Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in L... |
| CVE-2026-48055 | CRITICAL | 10 | 0.6% | Jun 17, 2026 | Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior,... |
| CVE-2026-47340 | MEDIUM | 6.5 | 0.4% | Jun 17, 2026 | Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. ... |
| CVE-2026-47277 | MEDIUM | 6.5 | 0.4% | Jun 17, 2026 | Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos fro... |
| CVE-2026-45436 | MEDIUM | 6.5 | 0.3% | Jun 17, 2026 | Subscriber Broken Access Control in WPBakery Page Builder <= 8.7.2 versions. |
| CVE-2026-44587 | MEDIUM | 6.1 | 0.2% | Jun 17, 2026 | CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_typ... |
| CVE-2026-42629 | HIGH | 8.8 | 0.3% | Jun 17, 2026 | Unauthenticated Broken Authentication in PowerPack Pro for Elementor < v2.13.0 versions. |
| CVE-2026-42385 | HIGH | 7.1 | 0.2% | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in Profile Builder Pro <= 3.15.0 versions. |
| CVE-2026-42380 | CRITICAL | 9.8 | 0.5% | Jun 17, 2026 | Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions. |
| CVE-2026-42357 | MEDIUM | 6.5 | 0.3% | Jun 17, 2026 | Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now