2026 CVE Vulnerabilities
61,214 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53840 | HIGH | 7.1 | 0.2% | Jun 16, 2026 | OpenClaw before 2026.5.12 contains an information disclosure vulnerability in streamable-http MCP servers that forwards ... |
| CVE-2026-50656 | HIGH | 7 | 10.7% | Jun 16, 2026 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicl... |
| CVE-2026-4367 | MEDIUM | 5.5 | 0.1% | Jun 16, 2026 | A flaw was found in libXpm. A local user with low privileges could exploit an Out-of-Bounds Read vulnerability in the `x... |
| CVE-2026-48775 | MEDIUM | 6.8 | 0.2% | Jun 16, 2026 | LangGraph SQLite Checkpoint is an implementation of LangGraph CheckpointSaver that uses SQLite DB (both sync and async, ... |
| CVE-2026-47964 | HIGH | 7.8 | 0.2% | Jun 16, 2026 | DNG SDK versions 1.7.1 2536 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in ... |
| CVE-2026-47963 | MEDIUM | 5.5 | 0.2% | Jun 16, 2026 | DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosur... |
| CVE-2026-47934 | MEDIUM | 5.5 | 0.2% | Jun 16, 2026 | DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosur... |
| CVE-2026-47927 | MEDIUM | 5.5 | 0.2% | Jun 16, 2026 | DNG SDK versions 1.7.1 2536 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosur... |
| CVE-2026-47749 | HIGH | 7.8 | 0.2% | Jun 16, 2026 | stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Ima... |
| CVE-2026-47748 | MEDIUM | 5.5 | 0.2% | Jun 16, 2026 | stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Ima... |
| CVE-2026-10748 | HIGH | 8.6 | 0.3% | Jun 16, 2026 | An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbi... |
| CVE-2026-53776 | CRITICAL | 9.3 | 0.4% | Jun 16, 2026 | Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by... |
| CVE-2026-44932 | HIGH | 8.8 | 0.3% | Jun 16, 2026 | Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attac... |
| CVE-2026-42089 | HIGH | 8.6 | 0.1% | Jun 16, 2026 | Yeoman Environment provides an API to discover, create, and run generators, and to configure where and how a generator i... |
| CVE-2026-39927 | — | — | — | Jun 16, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-39926 | — | — | — | Jun 16, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-24228 | HIGH | 7.8 | 0.2% | Jun 16, 2026 | NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. ... |
| CVE-2026-24155 | HIGH | 7.8 | 0.2% | Jun 16, 2026 | NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerabil... |
| CVE-2026-12412 | — | — | — | Jun 16, 2026 | Rejected reason: loading template... |
| CVE-2026-12003 | MEDIUM | 5.3 | 0.1% | Jun 16, 2026 | To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is... |
| CVE-2026-10649 | HIGH | 8.6 | 0.6% | Jun 16, 2026 | A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the r... |
| CVE-2026-9307 | MEDIUM | 6.3 | 0.3% | Jun 16, 2026 | A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's ... |
| CVE-2026-48780 | HIGH | 8.2 | 0.2% | Jun 16, 2026 | Forem is open source software for building communities. Prior to commit a2ab6d4, a maliciously crafted email address cou... |
| CVE-2026-47684 | HIGH | 7.7 | 0.2% | Jun 16, 2026 | Sync-in Server is a secure, open-source platform for file storage, sharing, collaboration, and syncing. Prior to version... |
| CVE-2026-12398 | HIGH | 7.5 | 0.9% | Jun 16, 2026 | A command injection vulnerability was found in galaxy_ng. The do_git_checkout() function in the legacy role import API (... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now