2026 CVE Vulnerabilities
61,770 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45287 | MEDIUM | 5.5 | 0.2% | Jun 4, 2026 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to version 0.0.17, `go.opentelemetry.io/otel/schema/v1... |
| CVE-2026-44393 | HIGH | 7.4 | 0.2% | Jun 4, 2026 | An issue was discovered in OpenStack oslo.messaging 1.0.0 through 17.3.0. The oslo.messaging RabbitMQ driver does not pe... |
| CVE-2026-43986 | CRITICAL | 9.9 | 0.3% | Jun 4, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose a public ... |
| CVE-2026-43985 | HIGH | 8.8 | 0.1% | Jun 4, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `configUp... |
| CVE-2026-43984 | HIGH | 8.9 | 0.2% | Jun 4, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `log_js_e... |
| CVE-2026-41178 | MEDIUM | 5.3 | 0.2% | Jun 4, 2026 | OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and ... |
| CVE-2026-40930 | MEDIUM | 5.4 | 0.2% | Jun 4, 2026 | LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. I... |
| CVE-2026-38570 | HIGH | 7.5 | 0.3% | Jun 4, 2026 | bacnet_stack 1.3.1 contains an Out-of-bounds Read in bacnet_tag_number_decode which allows attackers to cause a denial o... |
| CVE-2026-36182 | CRITICAL | 9.8 | 0.2% | Jun 4, 2026 | GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, possibly allowing atta... |
| CVE-2026-10868 | CRITICAL | 9 | 0.2% | Jun 4, 2026 | A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplie... |
| CVE-2026-10815 | MEDIUM | 6.3 | 0.2% | Jun 4, 2026 | A vulnerability was found in LakshayD02 Hostel-Management-System-PHP up to f87e67c283bab6f718faf2fec6ae39a13bd7036b. Thi... |
| CVE-2026-10814 | HIGH | 7 | 0.1% | Jun 4, 2026 | A vulnerability has been found in milvus-io milvus up to 2.6.13. This vulnerability affects unknown code of the file int... |
| CVE-2026-10813 | LOW | 3.6 | 0.1% | Jun 4, 2026 | A flaw has been found in LMCache up to 0.4.6. This affects the function hex_hash_to_int16 of the file lmcache/integratio... |
| CVE-2026-47707 | MEDIUM | 5.3 | 0.4% | Jun 4, 2026 | Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.172.0 through0.315.6, the MaxAliasesLimiter ext... |
| CVE-2026-47706 | MEDIUM | 5.3 | 0.3% | Jun 4, 2026 | Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.71.0 through 0.315.6, the QueryDepthLimiter ext... |
| CVE-2026-45739 | MEDIUM | 4.3 | 0.2% | Jun 4, 2026 | Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.288.4 through 0.315.3, Strawberry's bundled Gra... |
| CVE-2026-41065 | HIGH | 8.9 | 0.4% | Jun 4, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 are vulnerable t... |
| CVE-2026-36180 | MEDIUM | 4.6 | 0.1% | Jun 4, 2026 | A lack of runtime integrity in GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass file system read-only pr... |
| CVE-2026-36178 | MEDIUM | 4.6 | 0.1% | Jun 4, 2026 | The factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic material in the JFFS2 configu... |
| CVE-2026-36176 | HIGH | 7.1 | 0.1% | Jun 4, 2026 | GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial c... |
| CVE-2026-36175 | MEDIUM | 6.8 | 0.2% | Jun 4, 2026 | An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and ... |
| CVE-2026-36174 | MEDIUM | 4.6 | 0.1% | Jun 4, 2026 | GNCC GP5 v7.1.76 was discovered to store sensitive wireless network information in plaintext during routine operations t... |
| CVE-2026-35906 | CRITICAL | 9.6 | 0.5% | Jun 4, 2026 | An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthenticated at... |
| CVE-2026-35905 | CRITICAL | 9.8 | 0.4% | Jun 4, 2026 | T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, and T7281 v1.0.03 were discovered to contain a hardcoded passw... |
| CVE-2026-35904 | CRITICAL | 9.8 | 0.5% | Jun 4, 2026 | Incorrect access control in the web management interface of T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03, an... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now