2026 CVE Vulnerabilities
61,327 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48546 | HIGH | 8.5 | 0.5% | Jun 11, 2026 | KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by expl... |
| CVE-2026-47157 | MEDIUM | 6.5 | 0.2% | Jun 11, 2026 | aiograpi is an asynchronous Instagram API for Python. aiograpi versions before 0.9.10 accepted server-supplied signup ch... |
| CVE-2026-46698 | MEDIUM | 5.3 | 0.2% | Jun 11, 2026 | Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.9, Fediverse Embeds registered the unau... |
| CVE-2026-46697 | HIGH | 7.5 | 0.2% | Jun 11, 2026 | Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unaut... |
| CVE-2026-3329 | HIGH | 7.5 | 0.5% | Jun 11, 2026 | A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype N... |
| CVE-2026-11986 | MEDIUM | 4.9 | 0.3% | Jun 11, 2026 | A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabi... |
| CVE-2026-49982 | HIGH | 8.2 | 0.5% | Jun 11, 2026 | tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects ... |
| CVE-2026-44705 | HIGH | 8.2 | 0.4% | Jun 11, 2026 | tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal... |
| CVE-2026-44496 | HIGH | 7.5 | 0.7% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and befor... |
| CVE-2026-44495 | HIGH | 7.7 | 0.8% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contain... |
| CVE-2026-44494 | HIGH | 8.7 | 1.0% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vuln... |
| CVE-2026-44492 | HIGH | 8.6 | 0.9% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise I... |
| CVE-2026-44490 | HIGH | 8.2 | 0.3% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-sid... |
| CVE-2026-44489 | MEDIUM | 5.3 | 0.2% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created b... |
| CVE-2026-44488 | HIGH | 7.5 | 0.7% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce co... |
| CVE-2026-44487 | HIGH | 7.5 | 0.7% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapt... |
| CVE-2026-44486 | HIGH | 7.5 | 0.7% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapte... |
| CVE-2026-11945 | HIGH | 7.5 | 0.2% | Jun 11, 2026 | PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON docume... |
| CVE-2026-9648 | CRITICAL | 9.1 | 0.2% | Jun 11, 2026 | The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certi... |
| CVE-2026-7870 | HIGH | 8.8 | 0.3% | Jun 11, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malici... |
| CVE-2026-7787 | HIGH | 8.1 | 0.2% | Jun 11, 2026 | IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypass... |
| CVE-2026-53777 | HIGH | 8.6 | 0.4% | Jun 11, 2026 | Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary co... |
| CVE-2026-4096 | MEDIUM | 6.1 | 0.1% | Jun 11, 2026 | IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by th... |
| CVE-2026-3341 | MEDIUM | 5.4 | 0.1% | Jun 11, 2026 | IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allo... |
| CVE-2026-11839 | CRITICAL | 9.9 | 0.3% | Jun 11, 2026 | Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now