2026 CVE Vulnerabilities
61,340 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9743 | HIGH | 7.1 | 0.3% | Jun 9, 2026 | In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines... |
| CVE-2026-9742 | MEDIUM | 5.9 | 0.3% | Jun 9, 2026 | When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of th... |
| CVE-2026-9741 | HIGH | 7.1 | 0.1% | Jun 9, 2026 | A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side F... |
| CVE-2026-9740 | HIGH | 8.7 | 0.3% | Jun 9, 2026 | A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by ... |
| CVE-2026-9735 | MEDIUM | 6.8 | 0.1% | Jun 9, 2026 | MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. W... |
| CVE-2026-46433 | MEDIUM | 6.5 | 0.2% | Jun 9, 2026 | lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1.0.22, lldpd_decode() in src/daemon/lldpd.c strips ... |
| CVE-2026-46374 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to vers... |
| CVE-2026-46373 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to vers... |
| CVE-2026-44963 | CRITICAL | 9.4 | 2.0% | Jun 9, 2026 | A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. |
| CVE-2026-10238 | — | — | — | Jun 9, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-47905 | MEDIUM | 6.2 | 0.2% | Jun 9, 2026 | CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu... |
| CVE-2026-47904 | MEDIUM | 6.2 | 0.2% | Jun 9, 2026 | CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu... |
| CVE-2026-47903 | MEDIUM | 6.2 | 0.2% | Jun 9, 2026 | CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation v... |
| CVE-2026-47902 | MEDIUM | 6.2 | 0.2% | Jun 9, 2026 | CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu... |
| CVE-2026-34713 | HIGH | 7.5 | 0.4% | Jun 9, 2026 | CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu... |
| CVE-2026-34712 | HIGH | 7.5 | 0.4% | Jun 9, 2026 | CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation v... |
| CVE-2026-34711 | HIGH | 7.5 | 0.4% | Jun 9, 2026 | CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Integer Overflow or Wraparo... |
| CVE-2026-34657 | MEDIUM | 5.5 | 0.2% | Jun 9, 2026 | CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Limitation of a Pa... |
| CVE-2026-34417 | MEDIUM | 6.1 | 0.2% | Jun 9, 2026 | OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbit... |
| CVE-2026-25860 | MEDIUM | 6.1 | 0.3% | Jun 9, 2026 | OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that al... |
| CVE-2026-48303 | CRITICAL | 10 | 0.6% | Jun 9, 2026 | Adobe Campaign Classic (ACC) versions 7.4.3 build 9394 and earlier are affected by an Incorrect Authorization vulnerabil... |
| CVE-2026-48292 | HIGH | 7.8 | 0.3% | Jun 9, 2026 | Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result i... |
| CVE-2026-48291 | HIGH | 7.8 | 0.3% | Jun 9, 2026 | Format Plugins versions 1.1.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result i... |
| CVE-2026-47961 | MEDIUM | 5.5 | 0.2% | Jun 9, 2026 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that ... |
| CVE-2026-47960 | HIGH | 7.4 | 0.5% | Jun 9, 2026 | ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Restriction of XML External Entity Reference... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now