2026 CVE Vulnerabilities
61,333 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48107 | MEDIUM | 6.5 | 0.2% | Jun 10, 2026 | Russh is a Rust SSH client & server library. From version 0.37.0 to before version 0.61.0, in the russh client keyboard-... |
| CVE-2026-48011 | LOW | 3.7 | 0.2% | Jun 10, 2026 | Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the us... |
| CVE-2026-46705 | MEDIUM | 5.3 | 0.2% | Jun 10, 2026 | Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, the russh server authe... |
| CVE-2026-46702 | HIGH | 7.5 | 0.3% | Jun 10, 2026 | Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.1, when SSH compression is enabl... |
| CVE-2026-46689 | HIGH | 8.7 | 0.3% | Jun 10, 2026 | Kanidm is an identity management platform. Prior to version 1.9.3, a single unauthenticated GET to any /scim/v1/... endp... |
| CVE-2026-46679 | HIGH | 7.5 | 0.3% | Jun 10, 2026 | libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 15.0.23, three cooperating omissions ... |
| CVE-2026-46673 | HIGH | 7.5 | 0.3% | Jun 10, 2026 | Russh is a Rust SSH client & server library. Prior to version 0.60.3, CryptoVec used unchecked capacity growth, unchecke... |
| CVE-2026-46669 | HIGH | 7.5 | 0.2% | Jun 10, 2026 | OpenVM is a performant and modular zkVM framework built for customization and extensibility. Prior to version 1.6.0, the... |
| CVE-2026-46668 | LOW | 2.3 | 0.3% | Jun 10, 2026 | SpiceDB is an open source database system for creating and managing security-critical application permissions. From vers... |
| CVE-2026-46654 | HIGH | 8.9 | 0.1% | Jun 10, 2026 | Plonky3 is a toolkit for polynomial IOPs (PIOPs). Prior to versions 0.4.3 and 0.5.3, an attacker controlling prover-side... |
| CVE-2026-46625 | HIGH | 7.5 | 0.9% | Jun 10, 2026 | JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal as... |
| CVE-2026-46523 | MEDIUM | 6.2 | 0.3% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.2... |
| CVE-2026-46522 | HIGH | 7.5 | 1.8% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.2... |
| CVE-2026-46520 | HIGH | 7.5 | 0.4% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-45783 | HIGH | 7.5 | 0.4% | Jun 10, 2026 | libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 16.2.6, an unauthenticated remote pee... |
| CVE-2026-45664 | MEDIUM | 5.3 | 0.4% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-45624 | MEDIUM | 5.1 | 0.1% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-45384 | MEDIUM | 6.1 | 0.1% | Jun 10, 2026 | bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4... |
| CVE-2026-45380 | LOW | 3.6 | 0.1% | Jun 10, 2026 | bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4... |
| CVE-2026-45359 | MEDIUM | 5.7 | 0.1% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-45358 | MEDIUM | 5.3 | 0.2% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-45031 | MEDIUM | 5.3 | 0.5% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-44692 | HIGH | 7.7 | 0.3% | Jun 10, 2026 | Sharp is a content management framework built for Laravel as a package. Prior to version 9.22.0, Sharp exposes a generic... |
| CVE-2026-42542 | HIGH | 7.5 | 0.5% | Jun 10, 2026 | TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3... |
| CVE-2026-42462 | HIGH | 7 | 0.2% | Jun 10, 2026 | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now