2026 CVE Vulnerabilities
61,320 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7387 | HIGH | 8.8 | 0.3% | Jun 12, 2026 | Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to req... |
| CVE-2026-7184 | MEDIUM | 6.5 | 0.3% | Jun 12, 2026 | Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15 fail to sanitize the Remote Cluster API resp... |
| CVE-2026-6961 | HIGH | 7.6 | 0.3% | Jun 12, 2026 | Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to san... |
| CVE-2026-6739 | HIGH | 7.2 | 0.3% | Jun 12, 2026 | Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to require system-... |
| CVE-2026-6689 | MEDIUM | 4.3 | 0.2% | Jun 12, 2026 | Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Fail to enforce Permiss... |
| CVE-2026-6046 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to validate that a... |
| CVE-2026-53982 | HIGH | 7.1 | 0.3% | Jun 12, 2026 | Cap-go Console < 12.28.2 contains a denial-of-service vulnerability in its account deletion flow that allows an attacker... |
| CVE-2026-53981 | HIGH | 7.6 | 0.3% | Jun 12, 2026 | Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism that allows an attacke... |
| CVE-2026-47224 | MEDIUM | 4.3 | 0.2% | Jun 12, 2026 | NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6.... |
| CVE-2026-47222 | MEDIUM | 5.4 | 0.2% | Jun 12, 2026 | NanaZip is the 7-Zip derivative intended for the modern Windows experience. From version 3.0.1000.0 to before version 6.... |
| CVE-2026-3840 | HIGH | 7.1 | 0.2% | Jun 12, 2026 | A vulnerability in Kedro version 1.2.0 allows an attacker to exploit path traversal by providing a crafted version strin... |
| CVE-2026-3433 | MEDIUM | 4.3 | 0.2% | Jun 12, 2026 | Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to restrict role_u... |
| CVE-2026-9641 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default alg... |
| CVE-2026-9638 | HIGH | 7.5 | 0.3% | Jun 12, 2026 | Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts. These versions use the built... |
| CVE-2026-8828 | HIGH | 8.8 | 0.3% | Jun 12, 2026 | A lack of authorization validation in version 1.0.0 or later of the ChromaDB Rust project allows any authenticated users... |
| CVE-2026-5792 | MEDIUM | 6.5 | 0.2% | Jun 12, 2026 | Authentication bypass by spoofing vulnerability in Hedef Media Promotion Interactive Media Marketing Inc. Related Market... |
| CVE-2026-53568 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, there is a stored XSS vulnerab... |
| CVE-2026-50560 | MEDIUM | 5.3 | 0.3% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina... |
| CVE-2026-50091 | HIGH | 7.4 | 0.2% | Jun 12, 2026 | Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses h... |
| CVE-2026-50090 | MEDIUM | 6.1 | 0.3% | Jun 12, 2026 | The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due ... |
| CVE-2026-50089 | MEDIUM | 6.1 | 0.1% | Jun 12, 2026 | The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redire... |
| CVE-2026-50088 | MEDIUM | 4.7 | 0.2% | Jun 12, 2026 | The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test.aqara... |
| CVE-2026-50087 | MEDIUM | 6.1 | 0.2% | Jun 12, 2026 | The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is an inst... |
| CVE-2026-50086 | CRITICAL | 9.8 | 0.2% | Jun 12, 2026 | The Aqara IAM/SSO gateway (gw-builder.aqara.com) exposes bidirectional AES round-trups against the platform's signing ke... |
| CVE-2026-50085 | CRITICAL | 9.8 | 0.3% | Jun 12, 2026 | The Aqara Board service (op-test.aqara.com) accepts arbitrary MQTT command payloads, and forwards them to the platfom's ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now