2026 CVE Vulnerabilities
61,548 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11790 | MEDIUM | 4.9 | 0.3% | Jun 9, 2026 | A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on t... |
| CVE-2026-11789 | MEDIUM | 6.5 | 0.3% | Jun 9, 2026 | A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when comp... |
| CVE-2026-11788 | HIGH | 7.5 | 0.6% | Jun 9, 2026 | A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before us... |
| CVE-2026-11787 | MEDIUM | 6.3 | 0.2% | Jun 9, 2026 | A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without ... |
| CVE-2026-11786 | MEDIUM | 6.5 | 0.2% | Jun 9, 2026 | A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute ... |
| CVE-2026-11785 | MEDIUM | 4.3 | 0.2% | Jun 9, 2026 | A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial st... |
| CVE-2026-46324 | HIGH | 7.8 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: use list_del_rcu for netlink ... |
| CVE-2026-46323 | HIGH | 7.8 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: gro: don't merge zcopy skbs skb_gro_receive()... |
| CVE-2026-46322 | HIGH | 7.1 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: tun: free page on build_skb failure in tun_xdp_one(... |
| CVE-2026-46321 | HIGH | 7.1 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun_xdp_... |
| CVE-2026-46320 | HIGH | 7.4 | 0.2% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: tap: free page on error paths in tap_get_user_xdp()... |
| CVE-2026-46319 | HIGH | 7.8 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: Only release RCU read lock after... |
| CVE-2026-46318 | MEDIUM | 5.5 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: Revert "mm/hugetlbfs: update hugetlbfs to use mmap_... |
| CVE-2026-46317 | HIGH | 8.8 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Reassign nested_mmus array behind mmu_l... |
| CVE-2026-46316 | CRITICAL | 9.3 | 0.4% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Drop the translation cache re... |
| CVE-2026-2638 | HIGH | 7.3 | 0.1% | Jun 9, 2026 | A vulnerability in the quarantine and restore workflow of the X-VPN macOS website versions 77.0 through 77.5 allow a loc... |
| CVE-2026-11764 | LOW | 3.6 | 0.2% | Jun 9, 2026 | When creating an export of all reusable media, the secrets of connected gift cards were included in the export even if ... |
| CVE-2026-49742 | HIGH | 7.1 | 0.3% | Jun 9, 2026 | Backend users with file download permissions were able to download files from the fallback storage of the file abstracti... |
| CVE-2026-49741 | HIGH | 8.7 | 0.2% | Jun 9, 2026 | Backend users with write access to the form_definition database table were able to directly create, update, or delete fo... |
| CVE-2026-49740 | MEDIUM | 6.3 | 0.2% | Jun 9, 2026 | TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry) deserialized PHP payloads without in... |
| CVE-2026-49738 | LOW | 2.1 | 0.4% | Jun 9, 2026 | The path allowance check in GeneralUtility::isAllowedAbsPath() performed a plain string prefix comparison without requir... |
| CVE-2026-47352 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission... |
| CVE-2026-47351 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission ch... |
| CVE-2026-47350 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | Backend users were able to move records to a different page without having edit permissions on the source page. This iss... |
| CVE-2026-47349 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they w... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now