2026 CVE Vulnerabilities
61,215 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9261 | CRITICAL | 9.8 | 0.2% | Jun 16, 2026 | Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier |
| CVE-2026-9260 | CRITICAL | 9.8 | 0.2% | Jun 16, 2026 | Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier |
| CVE-2026-9259 | CRITICAL | 9.8 | 0.2% | Jun 16, 2026 | Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier |
| CVE-2026-9258 | CRITICAL | 9.8 | 0.3% | Jun 16, 2026 | Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier |
| CVE-2026-53430 | HIGH | 8.7 | 0.3% | Jun 15, 2026 | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-grpc grpc (GRPC.Compressor.Gzip... |
| CVE-2026-48854 | HIGH | 8.7 | 0.3% | Jun 15, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers ... |
| CVE-2026-48853 | CRITICAL | 9.2 | 0.6% | Jun 15, 2026 | Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grp... |
| CVE-2026-48723 | HIGH | 7.8 | 0.5% | Jun 15, 2026 | The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on BrowserStack. Versions pri... |
| CVE-2026-48599 | HIGH | 7.6 | 0.3% | Jun 15, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to acc... |
| CVE-2026-12205 | CRITICAL | 9.1 | 0.3% | Jun 15, 2026 | Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DS... |
| CVE-2026-5064 | HIGH | 8.5 | 0.1% | Jun 15, 2026 | Potential security vulnerabilities have been identified in the HP One Agent for certain HP PC products, which might all... |
| CVE-2026-48714 | CRITICAL | 9.1 | 0.4% | Jun 15, 2026 | i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno... |
| CVE-2026-48713 | CRITICAL | 9.1 | 0.4% | Jun 15, 2026 | Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missi... |
| CVE-2026-48157 | MEDIUM | 6.1 | 0.2% | Jun 15, 2026 | Slim is a PHP micro framework that enables users to write simple web applications and APIs. In versions 4.4.0 through 4.... |
| CVE-2026-48017 | HIGH | 8.8 | 0.5% | Jun 15, 2026 | DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate... |
| CVE-2026-12087 | CRITICAL | 9.1 | 0.4% | Jun 15, 2026 | Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the l... |
| CVE-2026-11832 | CRITICAL | 9.1 | 0.3% | Jun 15, 2026 | Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was genera... |
| CVE-2026-9691 | CRITICAL | 9.8 | 0.5% | Jun 15, 2026 | Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja For... |
| CVE-2026-52703 | CRITICAL | 9.6 | 0.3% | Jun 15, 2026 | Unauthenticated Path Traversal in FastDup <= 2.7.2 versions. |
| CVE-2026-52702 | HIGH | 7.1 | 0.1% | Jun 15, 2026 | Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions. |
| CVE-2026-52700 | HIGH | 8.5 | 0.3% | Jun 15, 2026 | Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions. |
| CVE-2026-52699 | HIGH | 7.5 | 0.2% | Jun 15, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions. |
| CVE-2026-52697 | HIGH | 8.5 | 0.3% | Jun 15, 2026 | Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions. |
| CVE-2026-52695 | HIGH | 7.5 | 0.2% | Jun 15, 2026 | Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions. |
| CVE-2026-52694 | HIGH | 7.5 | 0.2% | Jun 15, 2026 | Unauthenticated Sensitive Data Exposure in Signature Add-On for WooCommerce <= 2.0 versions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now