2026 CVE Vulnerabilities
61,244 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53705 | HIGH | 7.6 | 0.4% | Jun 15, 2026 | A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack f... |
| CVE-2026-53704 | HIGH | 7.1 | 0.2% | Jun 15, 2026 | A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file cont... |
| CVE-2026-53703 | HIGH | 7.1 | 0.2% | Jun 15, 2026 | A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file,... |
| CVE-2026-52722 | HIGH | 7.1 | 0.4% | Jun 15, 2026 | A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor d... |
| CVE-2026-52721 | MEDIUM | 5.3 | 0.1% | Jun 15, 2026 | Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trig... |
| CVE-2026-52720 | HIGH | 8.8 | 0.6% | Jun 15, 2026 | A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorr... |
| CVE-2026-52719 | HIGH | 7.1 | 0.3% | Jun 15, 2026 | An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser rea... |
| CVE-2026-52718 | MEDIUM | 6.5 | 0.3% | Jun 15, 2026 | A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse... |
| CVE-2026-50892 | MEDIUM | 6.5 | 0.2% | Jun 15, 2026 | Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows auth... |
| CVE-2026-50891 | HIGH | 8.1 | 0.3% | Jun 15, 2026 | Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges ... |
| CVE-2026-50890 | CRITICAL | 9.8 | 0.3% | Jun 15, 2026 | Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-group parameter at /sto... |
| CVE-2026-50889 | HIGH | 7.5 | 0.5% | Jun 15, 2026 | An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (... |
| CVE-2026-50888 | HIGH | 8.1 | 0.2% | Jun 15, 2026 | An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillec... |
| CVE-2026-50887 | CRITICAL | 9.1 | 0.3% | Jun 15, 2026 | A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attac... |
| CVE-2026-50886 | CRITICAL | 9.1 | 0.3% | Jun 15, 2026 | Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan inte... |
| CVE-2026-50885 | HIGH | 7.5 | 0.3% | Jun 15, 2026 | Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attackers to... |
| CVE-2026-50884 | HIGH | 8.8 | 0.3% | Jun 15, 2026 | Incorrect access control in statping-ng v0.93.0 allows attackers to escalate privileges to Administrator and access sens... |
| CVE-2026-50883 | CRITICAL | 9.6 | 0.4% | Jun 15, 2026 | An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute ... |
| CVE-2026-50882 | HIGH | 7.5 | 0.3% | Jun 15, 2026 | An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Denial of Service (DoS)... |
| CVE-2026-50881 | HIGH | 8.1 | 0.2% | Jun 15, 2026 | Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate p... |
| CVE-2026-50880 | CRITICAL | 9.8 | 0.5% | Jun 15, 2026 | An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary cod... |
| CVE-2026-50879 | HIGH | 7.5 | 0.3% | Jun 15, 2026 | An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Ser... |
| CVE-2026-50878 | HIGH | 7.5 | 0.4% | Jun 15, 2026 | An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Serv... |
| CVE-2026-50877 | HIGH | 7.5 | 0.6% | Jun 15, 2026 | An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory traversal via supplying files with names cont... |
| CVE-2026-50876 | MEDIUM | 5.4 | 0.2% | Jun 15, 2026 | A cross-site scripting (XSS) vulnerability in Deck9 Input v2.0.1 allows attackers to execute arbitrary web scripts or HT... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now