2026 CVE Vulnerabilities
61,320 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45416 | HIGH | 7.5 | 0.9% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina... |
| CVE-2026-44894 | HIGH | 7.5 | 0.1% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. NoQuicTokenHandler is the toke... |
| CVE-2026-44893 | HIGH | 7.5 | 0.6% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior t... |
| CVE-2026-44205 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to version 15.106.0, a stored XSS vulnerability in the user prof... |
| CVE-2026-41581 | MEDIUM | 6.9 | 0.2% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, there is a possible SQL Inject... |
| CVE-2026-10557 | CRITICAL | 9.8 | 0.4% | Jun 12, 2026 | The Yarbo Android and iOS applications contain hard-coded MQTT broker credentials that are identical for all users and a... |
| CVE-2026-28975 | MEDIUM | 6.9 | — | Jun 12, 2026 | ### Impact When `NIOHTTPRequestDecompressor` is configured with `.ratio(N)`, the decompression limit is enforced using ... |
| CVE-2026-28980 | HIGH | 8.7 | — | Jun 12, 2026 | ### Summary The `HTTPDecoder` in `NIOHTTP1` enforces no limit on the total size of an HTTP/1 message's header block or ... |
| CVE-2026-43671 | HIGH | 8.3 | — | Jun 12, 2026 | ### Summary A program using swift-nio is vulnerable to a potential out-of-bounds write when attacker-controlled index o... |
| CVE-2026-28970 | MEDIUM | 6.3 | — | Jun 12, 2026 | Programs using swift-nio is vulnerable to HTTP request smuggling and HTTP response splitting attacks, caused by insuffic... |
| CVE-2026-54102 | — | — | — | Jun 12, 2026 | Rejected reason: Reserved but no longer needed. |
| CVE-2026-54101 | — | — | — | Jun 12, 2026 | Rejected reason: Reserved but no longer needed. |
| CVE-2026-49993 | MEDIUM | 5.7 | 0.3% | Jun 12, 2026 | Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder from vers... |
| CVE-2026-47200 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.11.0 to before 3.21.6 and 4.0.0-alpha.1 ... |
| CVE-2026-46342 | MEDIUM | 5.4 | 0.1% | Jun 12, 2026 | Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.1.0 to before 3.21.6 and 4.0.0-alpha.1 t... |
| CVE-2026-45670 | MEDIUM | 5.4 | 0.2% | Jun 12, 2026 | Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder versions ... |
| CVE-2026-45669 | MEDIUM | 5.4 | 0.2% | Jun 12, 2026 | Nuxt is an open-source web development framework for Vue.js. From versions 3.4.3 to before 3.21.6 and 4.0.0-alpha.1 to b... |
| CVE-2026-1836 | MEDIUM | 5.3 | 0.1% | Jun 12, 2026 | The system stores the username and password from the login form after submitting the request. This could allow an attack... |
| CVE-2026-12066 | HIGH | 7.3 | 0.3% | Jun 12, 2026 | A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the fi... |
| CVE-2026-12065 | LOW | 1.8 | 0.1% | Jun 12, 2026 | A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This affects an unknown ... |
| CVE-2026-11967 | HIGH | 8.5 | 0.1% | Jun 12, 2026 | MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading a ma... |
| CVE-2026-11879 | HIGH | 8.5 | 0.1% | Jun 12, 2026 | MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading mali... |
| CVE-2026-49347 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | Quest Bot is an opensource Discord Bot. Prior to version 1.1.8, any user who can access the ticket panel can repeatedly ... |
| CVE-2026-48485 | LOW | 2.1 | 0.3% | Jun 12, 2026 | Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the latest release suppresses mentions when creating, un... |
| CVE-2026-47197 | HIGH | 7.2 | 0.2% | Jun 12, 2026 | Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, a moderator with the relevant Discord permission bit can... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now