2026 CVE Vulnerabilities
61,340 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-29114 | LOW | 2.3 | 0.2% | Jun 10, 2026 | A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that ... |
| CVE-2026-11815 | MEDIUM | 5.3 | 0.3% | Jun 10, 2026 | An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could pote... |
| CVE-2026-10846 | HIGH | 7.5 | 0.1% | Jun 10, 2026 | NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks m... |
| CVE-2026-26241 | CRITICAL | 9.1 | 0.3% | Jun 10, 2026 | A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vu... |
| CVE-2026-26240 | CRITICAL | 9.1 | 0.3% | Jun 10, 2026 | A buffer overflow vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vu... |
| CVE-2026-11837 | HIGH | 7.3 | 0.2% | Jun 10, 2026 | A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() ... |
| CVE-2026-26239 | HIGH | 8.1 | 0.3% | Jun 10, 2026 | A buffer overflow vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, t... |
| CVE-2026-26237 | HIGH | 7.5 | 0.3% | Jun 10, 2026 | A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vul... |
| CVE-2026-24724 | HIGH | 8.1 | 0.3% | Jun 10, 2026 | An incorrect authorization vulnerability has been reported to affect File Station 6. If a remote attacker gains a user a... |
| CVE-2026-24720 | MEDIUM | 6.5 | 0.3% | Jun 10, 2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a r... |
| CVE-2026-24719 | HIGH | 7.2 | 1.0% | Jun 10, 2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack... |
| CVE-2026-24717 | MEDIUM | 6.5 | 0.4% | Jun 10, 2026 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker ... |
| CVE-2026-24716 | HIGH | 7.2 | 0.3% | Jun 10, 2026 | A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote... |
| CVE-2026-22899 | MEDIUM | 6.5 | 0.3% | Jun 10, 2026 | A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user a... |
| CVE-2026-22893 | HIGH | 7.2 | 1.0% | Jun 10, 2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack... |
| CVE-2026-46532 | MEDIUM | 4.6 | 0.2% | Jun 10, 2026 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.3, and 6.0... |
| CVE-2026-45542 | HIGH | 7.1 | 0.3% | Jun 10, 2026 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0... |
| CVE-2026-45541 | HIGH | 7.5 | 0.4% | Jun 10, 2026 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0... |
| CVE-2026-45329 | MEDIUM | 6.5 | 0.1% | Jun 10, 2026 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secu... |
| CVE-2026-45328 | HIGH | 8.8 | 0.1% | Jun 10, 2026 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee componen... |
| CVE-2026-45160 | MEDIUM | 6.5 | 0.2% | Jun 10, 2026 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5.4.4, 5.5.4, and 6.0... |
| CVE-2026-46546 | MEDIUM | 5.4 | 0.1% | Jun 10, 2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version ... |
| CVE-2026-44634 | HIGH | 8.7 | 0.3% | Jun 10, 2026 | SimpleBLE is a cross-platform library and bindings for Bluetooth Low Energy (BLE). Prior to version 0.14.0, there are mu... |
| CVE-2026-53675 | MEDIUM | 5.3 | 0.2% | Jun 10, 2026 | BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any aut... |
| CVE-2026-53674 | HIGH | 7.1 | 0.3% | Jun 10, 2026 | BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when user... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now