2026 CVE Vulnerabilities
61,548 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25089 | CRITICAL | 9.8 | 36.1% | Jun 9, 2026 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F... |
| CVE-2026-24065 | HIGH | 8.1 | 0.3% | Jun 9, 2026 | Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability in the privile... |
| CVE-2026-24064 | HIGH | 7.8 | 0.2% | Jun 9, 2026 | Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability. A trusted XPC... |
| CVE-2026-10727 | HIGH | 7.2 | 1.6% | Jun 9, 2026 | An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote aut... |
| CVE-2026-10523 | CRITICAL | 9.8 | 47.2% | Jun 9, 2026 | An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allow... |
| CVE-2026-10520 | CRITICAL | 10 | 99.0% | Jun 9, 2026 | An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote ... |
| CVE-2026-9279 | HIGH | 8.7 | 0.3% | Jun 9, 2026 | Logseq exposes an IPC handler that allows the renderer process to execute shell commands. While an allowlist restricts t... |
| CVE-2026-7486 | CRITICAL | 9.8 | 0.3% | Jun 9, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Software In... |
| CVE-2026-52907 | HIGH | 7.8 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: media: rockchip: rkcif: fix off by one bugs Change... |
| CVE-2026-52906 | HIGH | 7.7 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: 9p: fix access mode flags being ORed instead of rep... |
| CVE-2026-52905 | MEDIUM | 5.5 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: disallow non-power of two min_region... |
| CVE-2026-52904 | MEDIUM | 5.5 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix nvkm_device leak on aperture remov... |
| CVE-2026-49762 | MEDIUM | 5.1 | 0.2% | Jun 9, 2026 | Uncontrolled Resource Consumption vulnerability in the Elixir standard library's Version module allows an attacker who c... |
| CVE-2026-47901 | MEDIUM | 4.6 | 0.1% | Jun 9, 2026 | Logseq is vulnerable to a sandbox escape flaw where plugins running in sandboxed iframes can inject arbitrary HTML attri... |
| CVE-2026-47900 | MEDIUM | 4.6 | 0.1% | Jun 9, 2026 | Logseq is vulnerable to a stored cross-site scripting (XSS). A malicious plugin can include a JavaScript payload in the ... |
| CVE-2026-47899 | HIGH | 8.7 | 0.1% | Jun 9, 2026 | The Electron preload script in Logseq exposes an API method that allows the renderer process to invoke IPC handlers with... |
| CVE-2026-46332 | HIGH | 8 | 0.2% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: greybus: gb-beagleplay: bound bootloader receive bu... |
| CVE-2026-46330 | HIGH | 7.8 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: Revert "net/smc: Introduce TCP ULP support" This r... |
| CVE-2026-46329 | MEDIUM | 5.5 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: erofs: handle end of filesystem properly for file-b... |
| CVE-2026-46328 | HIGH | 7.3 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix rlimit for posix cpu timers Posix cp... |
| CVE-2026-46327 | HIGH | 7.8 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm: fix unlocked test for dm_suspended_md The func... |
| CVE-2026-46326 | HIGH | 8.4 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: iio: pressure: mprls0025pa: fix spi_transfer struct... |
| CVE-2026-46325 | CRITICAL | 9.8 | 0.3% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix iova-to-va conversion for MR page siz... |
| CVE-2026-11793 | MEDIUM | 4.9 | 0.3% | Jun 9, 2026 | A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-co... |
| CVE-2026-11792 | LOW | 3.3 | 0.3% | Jun 9, 2026 | A heap buffer overflow flaw was found in 389 Directory Server. When audit logging is enabled, the create_masked_entry_st... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now