2026 CVE Vulnerabilities
61,679 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-36229 | — | — | — | Jun 6, 2026 | Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Fu... |
| CVE-2026-11441 | MEDIUM | 6.3 | 0.2% | Jun 6, 2026 | A vulnerability was identified in theonedev onedev up to 15.0.5. This vulnerability affects the function canAccessIssue ... |
| CVE-2026-11440 | MEDIUM | 6.3 | 0.2% | Jun 6, 2026 | A vulnerability was determined in theonedev onedev up to 15.0.5. This affects an unknown part of the file /repositories/... |
| CVE-2026-11439 | MEDIUM | 6.3 | 0.2% | Jun 6, 2026 | A vulnerability was found in theonedev onedev up to 15.0.5. Affected by this issue is some unknown functionality of the ... |
| CVE-2026-11438 | MEDIUM | 6.3 | 0.2% | Jun 6, 2026 | A vulnerability has been found in theonedev onedev up to 15.0.5. Affected by this vulnerability is an unknown functional... |
| CVE-2026-11437 | HIGH | 7.3 | 0.4% | Jun 6, 2026 | A flaw has been found in perfree go-fastdfs-web up to 1.3.7. Affected is the function checkServer of the file /install/c... |
| CVE-2026-11436 | MEDIUM | 4.3 | 0.3% | Jun 6, 2026 | A vulnerability was detected in Mage AI up to 0.9.79. This impacts the function useMutation of the file mage_ai/frontend... |
| CVE-2026-11435 | HIGH | 7.3 | 0.3% | Jun 6, 2026 | A security vulnerability has been detected in Jinher OA 1.0. This affects an unknown function of the file nextselectplan... |
| CVE-2026-11434 | LOW | 2.4 | 0.3% | Jun 6, 2026 | A weakness has been identified in FluentCMS 0.0.5. The impacted element is an unknown function of the file /admin/blocks... |
| CVE-2026-11413 | HIGH | 8.8 | 0.5% | Jun 6, 2026 | A security vulnerability has been detected in JingDong JD Cloud Box AX6600 4.5.3.r4546. The impacted element is the func... |
| CVE-2026-11412 | MEDIUM | 6.3 | 0.2% | Jun 6, 2026 | A weakness has been identified in Jinher OA C6. The affected element is an unknown function of the file /C6/JHSoft.Web.M... |
| CVE-2026-11411 | MEDIUM | 4.4 | 0.2% | Jun 6, 2026 | A security flaw has been discovered in iAI Lab PDF AI App 4.21.0 on Android. Impacted is the function getExternalCacheDi... |
| CVE-2026-11408 | MEDIUM | 6.3 | 1.1% | Jun 6, 2026 | A vulnerability was identified in vertex-app vertex up to 2026.02.12. This issue affects some unknown processing of the ... |
| CVE-2026-11406 | MEDIUM | 6.3 | 1.2% | Jun 6, 2026 | A vulnerability was determined in GL.iNet MT3000 up to 4.4.5. This vulnerability affects unknown code of the file ovpncl... |
| CVE-2026-10725 | HIGH | 7.5 | 0.4% | Jun 6, 2026 | Protocol::HTTP2 versions before 1.13 for Perl is vulnerable to a HTTP/2 Bomb. Protocol::HTTP2's inbound HPACK path has ... |
| CVE-2026-9851 | HIGH | 7.2 | 0.3% | Jun 6, 2026 | The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, a... |
| CVE-2026-9829 | MEDIUM | 6.5 | 0.3% | Jun 6, 2026 | The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQL Injectio... |
| CVE-2026-9594 | MEDIUM | 4.4 | 0.2% | Jun 6, 2026 | The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnera... |
| CVE-2026-9016 | MEDIUM | 5.3 | 0.3% | Jun 6, 2026 | The Debug Log Manager – Conveniently Monitor and Inspect Errors plugin for WordPress is vulnerable to Improper Output Ne... |
| CVE-2026-8839 | MEDIUM | 5.3 | 0.8% | Jun 6, 2026 | The MapPress Maps for WordPress plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key i... |
| CVE-2026-8611 | MEDIUM | 4.3 | 0.2% | Jun 6, 2026 | The Klamra Paycal for Aspaclaria plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions ... |
| CVE-2026-7624 | MEDIUM | 4.3 | 0.3% | Jun 6, 2026 | The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inc... |
| CVE-2026-9280 | MEDIUM | 6.1 | 0.2% | Jun 6, 2026 | The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL ... |
| CVE-2026-9197 | MEDIUM | 4.9 | 0.6% | Jun 6, 2026 | The Smart Slider 3 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.5.1... |
| CVE-2026-8991 | MEDIUM | 4.4 | 0.2% | Jun 6, 2026 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Script... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now