2026 CVE Vulnerabilities
61,244 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-38063 | CRITICAL | 9.8 | 1.0% | Jun 15, 2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via... |
| CVE-2026-38062 | CRITICAL | 9.8 | 1.0% | Jun 15, 2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via the rat... |
| CVE-2026-38061 | CRITICAL | 9.8 | 1.0% | Jun 15, 2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volum... |
| CVE-2026-38060 | CRITICAL | 9.8 | 1.0% | Jun 15, 2026 | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin p... |
| CVE-2026-37216 | MEDIUM | 6.1 | 0.2% | Jun 15, 2026 | Ruoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /system/notice/add. |
| CVE-2026-36933 | MEDIUM | 6.8 | 0.2% | Jun 15, 2026 | An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker to execute arbitrary code vi... |
| CVE-2026-36670 | HIGH | 8.8 | 0.4% | Jun 15, 2026 | A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) pr... |
| CVE-2026-36537 | CRITICAL | 9.8 | 0.5% | Jun 15, 2026 | ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The applica... |
| CVE-2026-36521 | MEDIUM | 6.1 | 0.2% | Jun 15, 2026 | PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in the site configuration management module. |
| CVE-2026-36213 | HIGH | 7.8 | 0.2% | Jun 15, 2026 | An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.e... |
| CVE-2026-30121 | CRITICAL | 9.1 | 0.3% | Jun 15, 2026 | remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability. |
| CVE-2026-30120 | CRITICAL | 9.8 | 0.8% | Jun 15, 2026 | remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability. |
| CVE-2026-11931 | MEDIUM | 6.8 | 0.1% | Jun 15, 2026 | Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication tok... |
| CVE-2026-8358 | MEDIUM | 5.4 | 0.2% | Jun 15, 2026 | LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document ... |
| CVE-2026-8357 | HIGH | 7.8 | 0.2% | Jun 15, 2026 | LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very... |
| CVE-2026-8356 | MEDIUM | 5.4 | 0.1% | Jun 15, 2026 | LibreOffice can import presentations in the legacy binary PPT format. A stack buffer overflow existed when importing a c... |
| CVE-2026-6047 | MEDIUM | 5.4 | 0.1% | Jun 15, 2026 | LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred pars... |
| CVE-2026-6045 | MEDIUM | 5.4 | 0.1% | Jun 15, 2026 | LibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow existed when importing ... |
| CVE-2026-6040 | HIGH | 7.3 | 0.1% | Jun 15, 2026 | A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read f... |
| CVE-2026-6039 | MEDIUM | 5.4 | 0.2% | Jun 15, 2026 | LibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow existed when importing a ... |
| CVE-2026-49294 | MEDIUM | 6.1 | 0.1% | Jun 15, 2026 | Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. Versions 3.6.3 and... |
| CVE-2026-47777 | HIGH | 7.5 | 0.2% | Jun 15, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in ... |
| CVE-2026-20262 | MEDIUM | 6.5 | 28.2% | Jun 15, 2026 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, r... |
| CVE-2026-9863 | HIGH | 8.8 | 0.6% | Jun 15, 2026 | Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy ta... |
| CVE-2026-9862 | CRITICAL | 9.8 | 1.0% | Jun 15, 2026 | Fortra's Core Privileged Access Manager (BoKS) contains an OS command injection vulnerability in the boks_autoregisterd... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now