2026 CVE Vulnerabilities
61,338 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-52751 | HIGH | 8.8 | 0.7% | Jun 10, 2026 | Ghidra before 12.1 contains an unsafe deserialization vulnerability in client-side Shared-Project RMI connection code th... |
| CVE-2026-52750 | HIGH | 8.4 | 0.5% | Jun 10, 2026 | Ghidra before 12.1 contains a command injection vulnerability in URL annotation handling on Windows where cmd.exe metach... |
| CVE-2026-49498 | HIGH | 8.8 | 0.3% | Jun 10, 2026 | Ghidra 11.0 before 12.1 contains a SQL injection vulnerability in the changePassword() method of PostgresFunctionDatabas... |
| CVE-2026-49497 | MEDIUM | 4.6 | 0.2% | Jun 10, 2026 | Ghidra before 12.1 contains a path traversal vulnerability in SameDirDebugInfoProvider that fails to validate filenames ... |
| CVE-2026-49496 | MEDIUM | 6.9 | 0.2% | Jun 10, 2026 | Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator ... |
| CVE-2026-49495 | MEDIUM | 6.7 | 0.2% | Jun 10, 2026 | Ghidra 10.2 before 12.1 contains an uncontrolled resource consumption vulnerability in ExportTrie.parseTrie() that lacks... |
| CVE-2026-49069 | HIGH | 7.1 | 0.1% | Jun 10, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM Portfolio a... |
| CVE-2026-24067 | HIGH | 8.4 | 0.1% | Jun 10, 2026 | Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.too... |
| CVE-2026-24066 | HIGH | 8.4 | 0.1% | Jun 10, 2026 | Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.too... |
| CVE-2026-11859 | LOW | 2 | 0.3% | Jun 10, 2026 | An HTML injection vulnerability in the "fetch links" email sent by Thinkst Applied Research Canarytokens, enabling Inter... |
| CVE-2026-3018 | HIGH | 7.5 | 1.4% | Jun 10, 2026 | The Newsletters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘wpmlsubscriber_id’ parameter in ... |
| CVE-2026-11853 | MEDIUM | 6.5 | 0.3% | Jun 10, 2026 | Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages... |
| CVE-2026-11852 | MEDIUM | 6.5 | 0.2% | Jun 10, 2026 | Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debus... |
| CVE-2026-9019 | MEDIUM | 6.4 | 0.2% | Jun 10, 2026 | The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderCol... |
| CVE-2026-8853 | MEDIUM | 4.4 | 0.2% | Jun 10, 2026 | The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all version... |
| CVE-2026-8613 | MEDIUM | 6.4 | 0.2% | Jun 10, 2026 | The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widge... |
| CVE-2026-10721 | HIGH | 8.4 | 0.1% | Jun 10, 2026 | Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache, and... |
| CVE-2026-9067 | CRITICAL | 9.1 | 0.4% | Jun 10, 2026 | The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend ... |
| CVE-2026-9060 | LOW | 3.5 | 0.1% | Jun 10, 2026 | The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and o... |
| CVE-2026-8071 | HIGH | 8.8 | 0.3% | Jun 10, 2026 | The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a cus... |
| CVE-2026-3326 | HIGH | 8.6 | 1.0% | Jun 10, 2026 | The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL state... |
| CVE-2026-29116 | HIGH | 8.7 | 0.4% | Jun 10, 2026 | A vulnerability has been found in some Dahua products could allow an unauthenticated remote attacker to send a specially... |
| CVE-2026-29115 | MEDIUM | 6.9 | 0.4% | Jun 10, 2026 | A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially c... |
| CVE-2026-29114 | LOW | 2.3 | 0.2% | Jun 10, 2026 | A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that ... |
| CVE-2026-11815 | MEDIUM | 5.3 | 0.3% | Jun 10, 2026 | An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could pote... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now