2026 CVE Vulnerabilities
61,244 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-50875 | HIGH | 8.1 | 0.3% | Jun 15, 2026 | Incorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows authenticated attackers... |
| CVE-2026-50874 | HIGH | 8.1 | 1.1% | Jun 15, 2026 | An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscence v0.3.0 allo... |
| CVE-2026-50873 | CRITICAL | 9.8 | 0.4% | Jun 15, 2026 | An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to exec... |
| CVE-2026-50872 | CRITICAL | 9.8 | 0.6% | Jun 15, 2026 | An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitra... |
| CVE-2026-50871 | CRITICAL | 9.8 | 1.6% | Jun 15, 2026 | An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscenc... |
| CVE-2026-50870 | HIGH | 7.5 | 0.3% | Jun 15, 2026 | An information disclosure vulnerability in the configuration endpoint of Ben Busby whoogle-search v1.2.3 allows attacker... |
| CVE-2026-50869 | CRITICAL | 9.8 | 0.7% | Jun 15, 2026 | An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplyi... |
| CVE-2026-49954 | HIGH | 8.6 | 0.5% | Jun 15, 2026 | Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that allows authenticated a... |
| CVE-2026-49953 | MEDIUM | 6.9 | 0.4% | Jun 15, 2026 | Discuz! X5.0 releases 20260320 through 20260610 contains a CAPTCHA bypass vulnerability that allows unauthenticated remo... |
| CVE-2026-49952 | CRITICAL | 9.3 | 0.5% | Jun 15, 2026 | Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthentica... |
| CVE-2026-48114 | CRITICAL | 9.8 | 0.4% | Jun 15, 2026 | Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.0.0 and and ab... |
| CVE-2026-47835 | HIGH | 7.5 | 0.3% | Jun 15, 2026 | In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearc... |
| CVE-2026-45390 | CRITICAL | 9.1 | 0.4% | Jun 15, 2026 | In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working dire... |
| CVE-2026-45389 | HIGH | 7.4 | 0.2% | Jun 15, 2026 | In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client ... |
| CVE-2026-45388 | CRITICAL | 9.1 | 0.2% | Jun 15, 2026 | In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server,... |
| CVE-2026-41708 | HIGH | 7.5 | 0.3% | Jun 15, 2026 | In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service ... |
| CVE-2026-39197 | MEDIUM | 6.5 | 0.3% | Jun 15, 2026 | An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Serv... |
| CVE-2026-39196 | CRITICAL | 9.8 | 0.3% | Jun 15, 2026 | Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in th... |
| CVE-2026-39118 | HIGH | 8.4 | 0.1% | Jun 15, 2026 | An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client valid... |
| CVE-2026-39007 | HIGH | 7.5 | 0.4% | Jun 15, 2026 | An issue in Observeinc's Observe v.2026-01-28 and before allows a remote attacker to obtain sensitive information via th... |
| CVE-2026-39006 | CRITICAL | 9.8 | 0.5% | Jun 15, 2026 | An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component... |
| CVE-2026-38812 | CRITICAL | 9.8 | 0.4% | Jun 15, 2026 | RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generatio... |
| CVE-2026-38329 | CRITICAL | 9.8 | 0.6% | Jun 15, 2026 | Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoi... |
| CVE-2026-38065 | CRITICAL | 9.8 | 1.3% | Jun 15, 2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ... |
| CVE-2026-38064 | CRITICAL | 9.8 | 1.0% | Jun 15, 2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now