2026 CVE Vulnerabilities
61,767 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41237 | HIGH | 8.6 | 0.3% | Jun 4, 2026 | Froxlor is open source server administration software. In version 2.3.6 and earlier, the LOC record regex uses `\s+` whi... |
| CVE-2026-41236 | HIGH | 8.8 | 0.4% | Jun 4, 2026 | Froxlor is open source server administration software. Version 2.3.6 contains a symlink-following flaw in the root-owned... |
| CVE-2026-41235 | HIGH | 8.6 | 0.2% | Jun 4, 2026 | Froxlor is open source server administration software. Version 2.3.6 lets administrators configure `system.available_she... |
| CVE-2026-41234 | HIGH | 7.6 | 0.3% | Jun 4, 2026 | Froxlor is open source server administration software. Prior to version 2.3.7, the `DomainZones.add` API endpoint does n... |
| CVE-2026-40898 | HIGH | 7.5 | 0.3% | Jun 4, 2026 | quic-go is an implementation of the QUIC protocol in Go. Prior to version 0.59.1, an attacker can cause excessive memory... |
| CVE-2026-36499 | MEDIUM | 6.5 | 0.3% | Jun 4, 2026 | A missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB wr... |
| CVE-2026-50292 | CRITICAL | 9.8 | 0.5% | Jun 4, 2026 | In libinput before 1.30.4 and 1.31.x before 1.31.3, libinput-device-group unescaped phys output can inject udev properti... |
| CVE-2026-48040 | CRITICAL | 9.1 | 0.2% | Jun 4, 2026 | The netty incubator codec.bhttp is a java language binary http parser. The library implements Oblivious HTTP (RFC 9458) ... |
| CVE-2026-41207 | MEDIUM | 5.3 | 0.2% | Jun 4, 2026 | The netty incubator codec.bhttp is a java language binary http parser. Prior to version 0.0.21.Final, HKDF_expand return... |
| CVE-2026-25551 | HIGH | 7.8 | 0.1% | Jun 4, 2026 | Seagull Software BarTender 2021 R1 through 12.0.1 contains an insecure deserialization vulnerability that allows low-pri... |
| CVE-2026-25550 | CRITICAL | 9.8 | 0.9% | Jun 4, 2026 | Seagull Software BarTender 2010, 2016, and 2019 contain an unauthenticated remote code execution vulnerability in the .N... |
| CVE-2026-10880 | CRITICAL | 9.8 | 0.4% | Jun 4, 2026 | OSNexus QuantaStor SDS Manager is vulnerable to SQL injection in the login endpoint. The username field is not properly ... |
| CVE-2026-10796 | HIGH | 7.5 | 0.5% | Jun 4, 2026 | nvm (Node Version Manager) through 0.40.4 executes arbitrary commands from version strings supplied by the configured No... |
| CVE-2026-50266 | LOW | 2.2 | 0.3% | Jun 4, 2026 | In OpenStack Neutron before 28.0.1, a project manager can create or update a port on a shared network owned by another p... |
| CVE-2026-50076 | CRITICAL | 9.1 | 0.5% | Jun 4, 2026 | Deserialization of Untrusted Data in the Java replace-resolve path in Apache Fory fory-core Java SDK before 1.1.0 on Jav... |
| CVE-2026-49942 | HIGH | 7.3 | 0.3% | Jun 4, 2026 | Net::CIDR::Set versions through 0.20 for Perl did not validate network masks. The mask portion of a network mask could ... |
| CVE-2026-49941 | HIGH | 7.5 | 0.3% | Jun 4, 2026 | Net::CIDR::Set versions through 0.20 for Perl did not validate IP addresses. The add method called the _encode method t... |
| CVE-2026-49940 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addresses and netmasks. Unicode digits such as the Ar... |
| CVE-2026-46741 | HIGH | 7.5 | 0.3% | Jun 4, 2026 | Etsy::StatsD versions through 1.002002 for Perl allow metric injections. The metric names and values are not checked fo... |
| CVE-2026-46739 | MEDIUM | 5.3 | 0.3% | Jun 4, 2026 | Net::Statsd versions before 0.13 for Perl allow metric injections. The metric names are not checked for newlines, colon... |
| CVE-2026-7774 | MEDIUM | 6.9 | 0.6% | Jun 4, 2026 | tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names,... |
| CVE-2026-5228 | HIGH | 8.8 | 0.2% | Jun 4, 2026 | Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing... |
| CVE-2026-45287 | MEDIUM | 5.5 | 0.2% | Jun 4, 2026 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.0.17, `go.opentelemetry.io/otel/schema/v1... |
| CVE-2026-44393 | HIGH | 7.4 | 0.2% | Jun 4, 2026 | An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not pe... |
| CVE-2026-43986 | CRITICAL | 9.9 | 0.3% | Jun 4, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose a public ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now