2026 CVE Vulnerabilities
61,320 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-50084 | MEDIUM | 6.5 | 0.2% | Jun 12, 2026 | The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to... |
| CVE-2026-50083 | CRITICAL | 9.8 | 0.2% | Jun 12, 2026 | The Aqara IAM/SSO Gateway (gw-builder.aqara.com) used a hardcoded OAuth client credential, which is an instance of "CWE-... |
| CVE-2026-50082 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the att... |
| CVE-2026-50026 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, a lack of permission checks in... |
| CVE-2026-50020 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina... |
| CVE-2026-50011 | HIGH | 7.5 | 0.5% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina... |
| CVE-2026-50010 | HIGH | 7.5 | 0.5% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina... |
| CVE-2026-50009 | MEDIUM | 4.8 | 0.2% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final,... |
| CVE-2026-48748 | HIGH | 7.5 | 0.4% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Starting in version 4.2.0.Fina... |
| CVE-2026-48059 | HIGH | 7.5 | 0.6% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina... |
| CVE-2026-48043 | HIGH | 7.5 | 0.6% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to ... |
| CVE-2026-48006 | HIGH | 7.5 | 0.7% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina... |
| CVE-2026-47691 | CRITICAL | 10 | 0.3% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina... |
| CVE-2026-47190 | MEDIUM | 4.4 | 0.3% | Jun 12, 2026 | IPAM is the IP address Manager for Cluster API Provider Metal3. Prior to versions 1.11.7, 1.12.4, and 1.13.0, the IPAM c... |
| CVE-2026-47182 | MEDIUM | 5.3 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to version 16.17.4, any authenticated user can access private fi... |
| CVE-2026-46690 | MEDIUM | 5.8 | 0.1% | Jun 12, 2026 | unbounded_spsc is an "unbounded" extension of bounded_spsc_queue. In versions 0.2.0 and prior, sender::send pointer-as-v... |
| CVE-2026-45833 | HIGH | 8.8 | 0.3% | Jun 12, 2026 | A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacke... |
| CVE-2026-45832 | HIGH | 8.8 | 0.3% | Jun 12, 2026 | All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorizatio... |
| CVE-2026-45831 | HIGH | 8.8 | 0.2% | Jun 12, 2026 | The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project eva... |
| CVE-2026-45830 | HIGH | 8.8 | 0.3% | Jun 12, 2026 | A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated us... |
| CVE-2026-44976 | MEDIUM | 5.3 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboard... |
| CVE-2026-44975 | MEDIUM | 5.3 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can res... |
| CVE-2026-44967 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | OpenTelemetry-cpp is the C++ implementation of OpenTelemetry. Prior to release 1.27.0, the OTLP HTTP exporters (traces/m... |
| CVE-2026-44208 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "su... |
| CVE-2026-44207 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, an IDOR vulnerability allows a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now