2026 CVE Vulnerabilities
61,333 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47165 | MEDIUM | 4.1 | 0.1% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-46703 | CRITICAL | 9.6 | 0.5% | Jun 10, 2026 | Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers ... |
| CVE-2026-46695 | CRITICAL | 10 | 0.3% | Jun 10, 2026 | Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers ... |
| CVE-2026-46693 | MEDIUM | 4.1 | 0.1% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-46692 | MEDIUM | 4.1 | 0.1% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-46645 | MEDIUM | 4.3 | 0.3% | Jun 10, 2026 | SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to version 0.25.1, the ajax_lookup endpoint in appli... |
| CVE-2026-46559 | MEDIUM | 4 | 0.1% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-46557 | MEDIUM | 6.2 | 0.1% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-23... |
| CVE-2026-46521 | MEDIUM | 5.5 | 0.1% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-44693 | HIGH | 8.8 | 0.2% | Jun 10, 2026 | Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. Prior to version 6.6.1, P... |
| CVE-2026-42568 | MEDIUM | 4.3 | 1.0% | Jun 10, 2026 | Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `or... |
| CVE-2026-42563 | HIGH | 7.7 | 0.6% | Jun 10, 2026 | Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to v... |
| CVE-2026-42558 | HIGH | 7.6 | 0.1% | Jun 10, 2026 | Xibo is an open source digital signage platform with a web content management system and Windows display player software... |
| CVE-2026-42305 | HIGH | 8.8 | 0.6% | Jun 10, 2026 | Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and prior t... |
| CVE-2026-53742 | MEDIUM | 5.4 | 0.1% | Jun 10, 2026 | Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the ... |
| CVE-2026-53741 | MEDIUM | 5.4 | 0.1% | Jun 10, 2026 | Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal withou... |
| CVE-2026-53740 | MEDIUM | 5.4 | 0.1% | Jun 10, 2026 | Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republi... |
| CVE-2026-53739 | MEDIUM | 5.1 | 0.1% | Jun 10, 2026 | Yoast Duplicate Post through 4.6 contains a cross-site request forgery vulnerability in the duplicate_post_dismiss_notic... |
| CVE-2026-53738 | HIGH | 8.1 | 0.2% | Jun 10, 2026 | Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handli... |
| CVE-2026-53737 | MEDIUM | 6.1 | 0.2% | Jun 10, 2026 | Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page.... |
| CVE-2026-53736 | MEDIUM | 5.1 | 0.1% | Jun 10, 2026 | Easy Twitter Feeds before 1.2.13 contains a cross-site request forgery vulnerability in the duplicate_post action handle... |
| CVE-2026-53634 | MEDIUM | 4.3 | 0.2% | Jun 10, 2026 | Sharp is a content management framework built for Laravel as a package. From version 9.0.0 to before version 9.22.3, the... |
| CVE-2026-50131 | HIGH | 8.6 | 0.3% | Jun 10, 2026 | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Fedify previously addressed SS... |
| CVE-2026-48110 | HIGH | 7.5 | 0.3% | Jun 10, 2026 | Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.0, several russh client and serv... |
| CVE-2026-48108 | MEDIUM | 5.3 | 0.3% | Jun 10, 2026 | Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, russh did not enforce ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now