2026 CVE Vulnerabilities
61,320 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47196 | HIGH | 8.4 | 0.2% | Jun 12, 2026 | Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the automod add command trims user input but does not re... |
| CVE-2026-47195 | HIGH | 7.1 | 0.2% | Jun 12, 2026 | Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the purge and slowmode commands check only guild-level p... |
| CVE-2026-9266 | HIGH | 7 | 0.1% | Jun 12, 2026 | A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial... |
| CVE-2026-11849 | CRITICAL | 9.8 | 0.4% | Jun 12, 2026 | The iRM-IEI Remote Management developed by IEI Integration Corp has a Hardcoded Credentials vulnerability, allowing una... |
| CVE-2026-11848 | HIGH | 7.9 | 0.3% | Jun 12, 2026 | The iRM-IEI Remote Management developed by IEI Integration Corp has a Missing Authentication vulnerability, allowing una... |
| CVE-2026-50645 | HIGH | 7.5 | 0.5% | Jun 12, 2026 | There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache... |
| CVE-2026-50634 | MEDIUM | 6.5 | 0.3% | Jun 12, 2026 | A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was... |
| CVE-2026-50633 | HIGH | 8.1 | 0.9% | Jun 12, 2026 | A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code exec... |
| CVE-2026-50632 | HIGH | 8.1 | 0.6% | Jun 12, 2026 | A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache... |
| CVE-2026-50631 | HIGH | 7.4 | 0.3% | Jun 12, 2026 | A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-u... |
| CVE-2026-50630 | MEDIUM | 6.5 | 0.4% | Jun 12, 2026 | A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate res... |
| CVE-2026-50629 | MEDIUM | 5.3 | 0.5% | Jun 12, 2026 | The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages wi... |
| CVE-2026-50628 | CRITICAL | 9.8 | 0.7% | Jun 12, 2026 | A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly all... |
| CVE-2026-50627 | CRITICAL | 9.1 | 0.4% | Jun 12, 2026 | The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tok... |
| CVE-2026-50623 | MEDIUM | 4.8 | 0.4% | Jun 12, 2026 | An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 't... |
| CVE-2026-49875 | CRITICAL | 9.8 | 0.5% | Jun 12, 2026 | Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary... |
| CVE-2026-48914 | MEDIUM | 6.7 | 0.2% | Jun 12, 2026 | A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of... |
| CVE-2026-11847 | MEDIUM | 5.3 | 0.3% | Jun 12, 2026 | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Path Traversal vulnerability, allowi... |
| CVE-2026-11846 | HIGH | 8.1 | 0.4% | Jun 12, 2026 | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File Deletion vulnerabilit... |
| CVE-2026-11845 | HIGH | 8.6 | 1.0% | Jun 12, 2026 | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a OS Command Injection vulnerability, al... |
| CVE-2026-11844 | MEDIUM | 6.9 | 0.4% | Jun 12, 2026 | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Arbitrary File Read vulnerability, all... |
| CVE-2026-12058 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed. |
| CVE-2026-11535 | CRITICAL | 9.4 | 0.2% | Jun 12, 2026 | An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unaut... |
| CVE-2026-9271 | MEDIUM | 5.9 | 0.1% | Jun 12, 2026 | Vulnerability Title |
| CVE-2026-9269 | LOW | 3.5 | 0.1% | Jun 12, 2026 | The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some o... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now