2026 CVE Vulnerabilities
61,338 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46612 | HIGH | 8.8 | 0.3% | Jun 10, 2026 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic... |
| CVE-2026-45062 | HIGH | 8.1 | 0.6% | Jun 10, 2026 | FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the splitPos() function... |
| CVE-2026-20260 | MEDIUM | 4.3 | 0.2% | Jun 10, 2026 | In Splunk SOAR (Security Orchestration, Automation, and Response) versions below 8.5.0, an unauthenticated attacker coul... |
| CVE-2026-20259 | MEDIUM | 5.5 | 0.2% | Jun 10, 2026 | In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.0, 10.3.2512.1... |
| CVE-2026-20258 | MEDIUM | 5.4 | 0.2% | Jun 10, 2026 | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25... |
| CVE-2026-20257 | MEDIUM | 5.7 | 0.2% | Jun 10, 2026 | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25... |
| CVE-2026-20256 | MEDIUM | 5.7 | 0.3% | Jun 10, 2026 | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25... |
| CVE-2026-20255 | MEDIUM | 5.7 | 0.2% | Jun 10, 2026 | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25... |
| CVE-2026-20254 | MEDIUM | 5.7 | 0.2% | Jun 10, 2026 | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25... |
| CVE-2026-20253 | CRITICAL | 9.8 | 88.2% | Jun 10, 2026 | In Splunk Enterprise 10.2 versions below 10.2.4 and 10 versions below 10.0.7, an unauthenticated user could create or tr... |
| CVE-2026-20252 | HIGH | 7.6 | 0.3% | Jun 10, 2026 | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.4.26... |
| CVE-2026-20251 | HIGH | 8.8 | 0.6% | Jun 10, 2026 | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.1... |
| CVE-2026-11596 | MEDIUM | 4.7 | 0.2% | Jun 10, 2026 | In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an au... |
| CVE-2026-11417 | HIGH | 7.3 | 0.9% | Jun 10, 2026 | OS command injection in the NodejsFunction local bundling pipeline in aws-cdk-lib before 2.245.0 (2.246.0 on Windows) mi... |
| CVE-2026-46616 | MEDIUM | 6.1 | 0.2% | Jun 10, 2026 | Umbraco is an ASP.NET CMS. Prior to versions 13.14.0 and 17.4.0, some of the Surface Controllers in the CMS provide to s... |
| CVE-2026-46609 | MEDIUM | 4.6 | 0.1% | Jun 10, 2026 | Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4.0, authenticated users are able to inject HTML int... |
| CVE-2026-53698 | MEDIUM | 6.5 | 0.3% | Jun 10, 2026 | Silverpeas through 6.4.6 mishandles the "Personal space" feature that is selected when no componentId is set. |
| CVE-2026-53694 | HIGH | 7.3 | 0.1% | Jun 10, 2026 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Nomachine allows Arg... |
| CVE-2026-53693 | MEDIUM | 6.9 | 0.3% | Jun 10, 2026 | A stored cross-site scripting vulnerability existed in MISP BSimVis tag rendering code. Several client-side rendering pa... |
| CVE-2026-49760 | MEDIUM | 5.5 | 0.1% | Jun 10, 2026 | Stack-based Buffer Overflow vulnerability in Erlang OTP (erl_interface) allows Stack-based Buffer Overflow. This vulner... |
| CVE-2026-49759 | HIGH | 8.2 | 0.5% | Jun 10, 2026 | Stack-based Buffer Overflow vulnerability in Erlang OTP erts (inet_drv) allows an unauthenticated remote attacker to cra... |
| CVE-2026-48860 | MEDIUM | 6.5 | 0.2% | Jun 10, 2026 | Reliance on IP Address for Authentication vulnerability in Erlang/OTP ssl (inet_tls_dist module) allows unauthenticated ... |
| CVE-2026-48859 | MEDIUM | 5.3 | 0.4% | Jun 10, 2026 | Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated rem... |
| CVE-2026-48858 | MEDIUM | 6.5 | 0.2% | Jun 10, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP bounce attacks and S... |
| CVE-2026-48856 | MEDIUM | 6.5 | 0.3% | Jun 10, 2026 | Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Dat... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now