2026 CVE Vulnerabilities
61,555 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49741 | HIGH | 8.7 | 0.2% | Jun 9, 2026 | Backend users with write access to the form_definition database table were able to directly create, update, or delete fo... |
| CVE-2026-49740 | MEDIUM | 6.3 | 0.2% | Jun 9, 2026 | TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry) deserialized PHP payloads without in... |
| CVE-2026-49738 | LOW | 2.1 | 0.4% | Jun 9, 2026 | The path allowance check in GeneralUtility::isAllowedAbsPath() performed a plain string prefix comparison without requir... |
| CVE-2026-47352 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission... |
| CVE-2026-47351 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission ch... |
| CVE-2026-47350 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | Backend users were able to move records to a different page without having edit permissions on the source page. This iss... |
| CVE-2026-47349 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they w... |
| CVE-2026-47348 | MEDIUM | 5.1 | 0.3% | Jun 9, 2026 | Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in... |
| CVE-2026-47347 | MEDIUM | 5.3 | 0.3% | Jun 9, 2026 | Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to open redirect attacks ... |
| CVE-2026-47346 | HIGH | 7.6 | 0.3% | Jun 9, 2026 | Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .F... |
| CVE-2026-47343 | HIGH | 7.2 | 0.2% | Jun 9, 2026 | Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on fold... |
| CVE-2026-11607 | HIGH | 7.6 | 0.2% | Jun 9, 2026 | Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, whi... |
| CVE-2026-52902 | MEDIUM | 4.7 | 0.1% | Jun 9, 2026 | A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize ... |
| CVE-2026-4058 | MEDIUM | 4.3 | 0.2% | Jun 9, 2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP... |
| CVE-2026-46749 | CRITICAL | 9.8 | 0.1% | Jun 9, 2026 | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application uses a pas... |
| CVE-2026-46748 | HIGH | 7.8 | 0.2% | Jun 9, 2026 | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected system includes a bina... |
| CVE-2026-46747 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application does not p... |
| CVE-2026-46746 | HIGH | 8.8 | 0.5% | Jun 9, 2026 | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application does not properly s... |
| CVE-2026-41031 | CRITICAL | 9.3 | 0.2% | Jun 9, 2026 | A Stored Cross-Site Scripting vulnerability in Vinna Process Monitor Version 4.0 Service Pack 1 (Build 63255) allows an ... |
| CVE-2026-24349 | HIGH | 8.2 | 0.1% | Jun 9, 2026 | A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Run... |
| CVE-2026-10731 | CRITICAL | 9.3 | 0.3% | Jun 9, 2026 | SQL injection in the ‘two_steps_auth_code’ parameter processed by the ‘twoStepsAuthVerification’ function within the ‘/u... |
| CVE-2026-8677 | MEDIUM | 6.4 | 0.2% | Jun 9, 2026 | The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stored... |
| CVE-2026-8599 | MEDIUM | 6.4 | 0.2% | Jun 9, 2026 | The MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable ... |
| CVE-2026-8365 | HIGH | 8.8 | 0.8% | Jun 9, 2026 | The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_... |
| CVE-2026-7542 | MEDIUM | 6.5 | 0.3% | Jun 9, 2026 | The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions 7.0 to 7.0.10. ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now