2026 CVE Vulnerabilities
61,215 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12293 | CRITICAL | 9.8 | 0.3% | Jun 16, 2026 | Use-after-free in the Graphics: WebGPU component. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
| CVE-2026-12292 | HIGH | 8.1 | 0.4% | Jun 16, 2026 | Incorrect boundary conditions in the Web Audio component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.1... |
| CVE-2026-12291 | HIGH | 8.8 | 0.4% | Jun 16, 2026 | Use-after-free in the Networking: HTTP component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firef... |
| CVE-2026-12290 | HIGH | 8.1 | 0.4% | Jun 16, 2026 | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115... |
| CVE-2026-12289 | HIGH | 8.8 | 0.4% | Jun 16, 2026 | Privilege escalation in the Graphics: WebRender component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.... |
| CVE-2026-8484 | MEDIUM | 4.8 | 0.1% | Jun 16, 2026 | A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" wrapper due to a lack of size verification for th... |
| CVE-2026-40750 | CRITICAL | 9.9 | 0.3% | Jun 16, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Sh... |
| CVE-2026-12225 | HIGH | 8.7 | 0.5% | Jun 16, 2026 | syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket 3.4.0.x contains an authentication bypass vu... |
| CVE-2026-10829 | HIGH | 8.6 | 0.5% | Jun 16, 2026 | A stack-based buffer overflow vulnerability has been found in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and earli... |
| CVE-2026-10828 | MEDIUM | 6.9 | 0.3% | Jun 16, 2026 | A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPor... |
| CVE-2026-8442 | HIGH | 8.1 | 0.5% | Jun 16, 2026 | The WP Review Slider Pro plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to and including 1... |
| CVE-2026-8176 | HIGH | 7.5 | 0.3% | Jun 16, 2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Esca... |
| CVE-2026-5416 | HIGH | 8.8 | 0.8% | Jun 16, 2026 | Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exp... |
| CVE-2026-54198 | HIGH | 7.1 | 0.1% | Jun 16, 2026 | Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.35 versions. |
| CVE-2026-54197 | MEDIUM | 6.5 | 0.2% | Jun 16, 2026 | Unauthenticated Sensitive Data Exposure in GetGenie <= 4.4.1 versions. |
| CVE-2026-54191 | HIGH | 7.1 | 0.1% | Jun 16, 2026 | Unauthenticated Cross Site Scripting (XSS) in Pods <= 3.3.8 versions. |
| CVE-2026-54190 | MEDIUM | 6.5 | 0.2% | Jun 16, 2026 | Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions. |
| CVE-2026-52715 | CRITICAL | 9.3 | 0.3% | Jun 16, 2026 | Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions. |
| CVE-2026-52714 | MEDIUM | 5.9 | 0.2% | Jun 16, 2026 | Unauthenticated Broken Access Control in SEO Plugin by Squirrly SEO <= 12.4.16 versions. |
| CVE-2026-52712 | HIGH | 7.6 | 0.2% | Jun 16, 2026 | Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions. |
| CVE-2026-52711 | HIGH | 7.5 | 0.2% | Jun 16, 2026 | Unauthenticated Broken Access Control in WooCommerce POS <= 1.8.14 versions. |
| CVE-2026-49774 | CRITICAL | 9.9 | 0.3% | Jun 16, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inc... |
| CVE-2026-49772 | CRITICAL | 9.3 | 0.2% | Jun 16, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / Stell... |
| CVE-2026-40809 | MEDIUM | 6.5 | 0.2% | Jun 16, 2026 | Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Contro... |
| CVE-2026-39581 | HIGH | 8.5 | 0.3% | Jun 16, 2026 | Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now