2026 CVE Vulnerabilities
61,679 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11511 | LOW | 3.5 | 0.2% | Jun 8, 2026 | A weakness has been identified in Bolt CMS up to 3.7.5. This vulnerability affects unknown code of the file src/Storage/... |
| CVE-2026-50752 | HIGH | 7.4 | 4.9% | Jun 8, 2026 | A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacke... |
| CVE-2026-50751 | CRITICAL | 9.3 | 82.6% | Jun 8, 2026 | A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows ... |
| CVE-2026-47430 | HIGH | 7.5 | 0.7% | Jun 8, 2026 | ## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` body ... |
| CVE-2026-3011 | MEDIUM | 6.4 | 0.2% | Jun 8, 2026 | The Recipe Card Blocks Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the recipe block's 'su... |
| CVE-2026-11569 | MEDIUM | 5.4 | 0.1% | Jun 8, 2026 | A flaw was found in Quay. The filedrop endpoint accepts any mime type without validation, allowing an authenticated user... |
| CVE-2026-11510 | MEDIUM | 6.3 | 0.2% | Jun 8, 2026 | A security flaw has been discovered in CodeAstro Leave Management System 1.0. This affects an unknown part of the file /... |
| CVE-2026-11509 | MEDIUM | 6.3 | 0.2% | Jun 8, 2026 | A vulnerability was identified in CodeAstro Leave Management System 1.0. Affected by this issue is some unknown function... |
| CVE-2026-11508 | MEDIUM | 6.3 | 0.2% | Jun 8, 2026 | A vulnerability was determined in CodeAstro Leave Management System 1.0. Affected by this vulnerability is an unknown fu... |
| CVE-2026-11507 | MEDIUM | 6.3 | 0.2% | Jun 8, 2026 | A vulnerability was found in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /admin/d... |
| CVE-2026-11506 | MEDIUM | 6.3 | 0.2% | Jun 8, 2026 | A vulnerability has been found in CodeAstro Leave Management System 1.0. This impacts an unknown function of the file /a... |
| CVE-2026-11505 | MEDIUM | 5 | 0.2% | Jun 8, 2026 | A flaw has been found in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This affects an... |
| CVE-2026-11504 | HIGH | 8.8 | 0.5% | Jun 8, 2026 | A vulnerability was detected in Tenda CX12L 16.03.53.12. The impacted element is the function setSchedWifi of the file /... |
| CVE-2026-9506 | HIGH | 8.7 | 0.5% | Jun 8, 2026 | This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController compo... |
| CVE-2026-11503 | HIGH | 8.8 | 0.5% | Jun 8, 2026 | A security vulnerability has been detected in Tenda CX12L 16.03.53.12. The affected element is the function form_fast_se... |
| CVE-2026-11502 | LOW | 3.1 | 0.3% | Jun 8, 2026 | A weakness has been identified in JeecgBoot up to 3.9.2. Impacted is the function HttpServletResponse.sendRedirect of th... |
| CVE-2026-11501 | HIGH | 7.3 | 0.3% | Jun 8, 2026 | A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. This issue affect... |
| CVE-2026-11500 | MEDIUM | 5 | 0.3% | Jun 8, 2026 | A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the f... |
| CVE-2026-41724 | MEDIUM | 5.4 | 0.3% | Jun 8, 2026 | VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with ... |
| CVE-2026-41723 | HIGH | 8 | 0.4% | Jun 8, 2026 | VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with ... |
| CVE-2026-41722 | MEDIUM | 5.4 | 0.3% | Jun 8, 2026 | VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with ... |
| CVE-2026-3238 | HIGH | 7.5 | 2.7% | Jun 8, 2026 | A flaw was found in Samba’s WINS server component when running as an Active Directory Domain Controller. The WINS protoc... |
| CVE-2026-11499 | CRITICAL | 9.8 | 6.6% | Jun 8, 2026 | A vulnerability was determined in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formDOMAINBLK of th... |
| CVE-2026-11498 | HIGH | 8.8 | 3.8% | Jun 8, 2026 | A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. Affected by this issue is the function asp_voip_Ot... |
| CVE-2026-11497 | HIGH | 8.8 | 0.4% | Jun 8, 2026 | A vulnerability has been found in D-Link DCS-5615 1.01.00. Affected by this vulnerability is an unknown functionality of... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now