2026 CVE Vulnerabilities
61,320 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44206 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, DB Schema Enumeration is possi... |
| CVE-2026-40677 | HIGH | 7.7 | 0.4% | Jun 12, 2026 | The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a man-in-the-middle atta... |
| CVE-2026-8694 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attack... |
| CVE-2026-7368 | HIGH | 8.6 | 0.3% | Jun 12, 2026 | The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether ... |
| CVE-2026-6853 | CRITICAL | 9.8 | 0.3% | Jun 12, 2026 | Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe Businesses Industry ... |
| CVE-2026-6211 | HIGH | 8.7 | 0.2% | Jun 12, 2026 | Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Access... |
| CVE-2026-54133 | CRITICAL | 9.8 | 0.3% | Jun 12, 2026 | jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON doc... |
| CVE-2026-53787 | CRITICAL | 9.8 | 3.7% | Jun 12, 2026 | Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerabili... |
| CVE-2026-53722 | MEDIUM | 5.4 | 0.2% | Jun 12, 2026 | Nuxt is an open-source web development framework for Vue.js. Prior to versions 3.21.7 and 4.4.7, <NuxtLink> did not vali... |
| CVE-2026-53721 | HIGH | 8.2 | 0.3% | Jun 12, 2026 | Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4... |
| CVE-2026-47739 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, stored XSS in Note was possibl... |
| CVE-2026-47244 | MEDIUM | 5.3 | 0.3% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina... |
| CVE-2026-47210 | CRITICAL | 9.8 | 0.5% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, a sandbox escape vulnerability in vm2 allows arbi... |
| CVE-2026-47209 | HIGH | 8.6 | 0.3% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the BaseHandler.set trap in bridge.js (line 1231)... |
| CVE-2026-47208 | CRITICAL | 10 | 0.5% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability... |
| CVE-2026-47141 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM exposes some process-wide observability bu... |
| CVE-2026-47140 | CRITICAL | 10 | 0.5% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangerous Node.js builtins ... |
| CVE-2026-47139 | HIGH | 8.6 | 0.3% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding public network builtins... |
| CVE-2026-47137 | CRITICAL | 10 | 0.4% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) ... |
| CVE-2026-47135 | HIGH | 8.7 | 0.3% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, Symbol.for override in setup-sandbox.js only inte... |
| CVE-2026-47131 | CRITICAL | 10 | 0.4% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__... |
| CVE-2026-46340 | HIGH | 7.5 | 0.6% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport... |
| CVE-2026-45674 | CRITICAL | 10 | 0.2% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina... |
| CVE-2026-45673 | MEDIUM | 6.8 | 0.3% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina... |
| CVE-2026-45536 | MEDIUM | 4 | 0.1% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now