2026 CVE Vulnerabilities
61,327 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11846 | HIGH | 8.1 | 0.4% | Jun 12, 2026 | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File Deletion vulnerabilit... |
| CVE-2026-11845 | HIGH | 8.6 | 1.0% | Jun 12, 2026 | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a OS Command Injection vulnerability, al... |
| CVE-2026-11844 | MEDIUM | 6.9 | 0.4% | Jun 12, 2026 | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Arbitrary File Read vulnerability, all... |
| CVE-2026-12058 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed. |
| CVE-2026-11535 | CRITICAL | 9.4 | 0.2% | Jun 12, 2026 | An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unaut... |
| CVE-2026-9271 | MEDIUM | 5.9 | 0.1% | Jun 12, 2026 | Vulnerability Title |
| CVE-2026-9269 | LOW | 3.5 | 0.1% | Jun 12, 2026 | The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some o... |
| CVE-2026-12060 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticate... |
| CVE-2026-12059 | HIGH | 8.8 | 0.4% | Jun 12, 2026 | The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability, allowing authenticated ... |
| CVE-2026-45169 | HIGH | 8.6 | 0.3% | Jun 12, 2026 | Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a v... |
| CVE-2026-44892 | HIGH | 7.5 | 0.3% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final,... |
| CVE-2026-48613 | MEDIUM | 5.9 | 0.2% | Jun 12, 2026 | SQL injection vulnerability in phpBB profile field migration due to improper handling of user-supplied profile field dat... |
| CVE-2026-48612 | HIGH | 8 | 0.1% | Jun 12, 2026 | Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow an... |
| CVE-2026-48611 | CRITICAL | 9.8 | 0.7% | Jun 12, 2026 | Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or ... |
| CVE-2026-48610 | HIGH | 8.1 | 0.3% | Jun 12, 2026 | Under certain network configurations, a malicious actor with access to network could exploit an Improper Access Control ... |
| CVE-2026-47370 | CRITICAL | 9.9 | 0.8% | Jun 12, 2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability... |
| CVE-2026-47369 | CRITICAL | 9.9 | 0.3% | Jun 12, 2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability... |
| CVE-2026-47368 | HIGH | 8.6 | 0.4% | Jun 12, 2026 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices runni... |
| CVE-2026-47367 | CRITICAL | 9.9 | 0.8% | Jun 12, 2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability... |
| CVE-2026-47366 | HIGH | 7.2 | 0.3% | Jun 12, 2026 | Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) al... |
| CVE-2026-47365 | CRITICAL | 9.9 | 0.4% | Jun 12, 2026 | Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated... |
| CVE-2026-20746 | MEDIUM | 6.3 | 0.3% | Jun 12, 2026 | Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust j... |
| CVE-2026-9125 | MEDIUM | 6.4 | 0.4% | Jun 12, 2026 | The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the ... |
| CVE-2026-45170 | HIGH | 8.8 | 0.1% | Jun 12, 2026 | Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios... |
| CVE-2026-11933 | HIGH | 8.8 | 0.4% | Jun 12, 2026 | A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now