2026 CVE Vulnerabilities
61,770 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10804 | MEDIUM | 4.7 | 0.1% | Jun 4, 2026 | A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/r... |
| CVE-2026-10803 | LOW | 3.6 | 0.1% | Jun 4, 2026 | A flaw has been found in MLflow up to 3.10.0. This issue affects the function mlflow.data.digest_utils of the file mlflo... |
| CVE-2026-10802 | MEDIUM | 4.3 | 0.3% | Jun 4, 2026 | A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unknown code in the libra... |
| CVE-2026-49077 | MEDIUM | 5.3 | 0.2% | Jun 4, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMembe... |
| CVE-2026-10801 | LOW | 3.6 | 0.1% | Jun 4, 2026 | A security vulnerability has been detected in modelscope ms-swift up to 4.2.0. This affects the function Template._save_... |
| CVE-2026-8916 | MEDIUM | 6.1 | 0.1% | Jun 4, 2026 | Out-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: b... |
| CVE-2026-50226 | MEDIUM | 5.3 | 0.2% | Jun 4, 2026 | Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrar... |
| CVE-2026-50225 | CRITICAL | 9.1 | 0.2% | Jun 4, 2026 | The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems t... |
| CVE-2026-50224 | MEDIUM | 4.9 | 0.2% | Jun 4, 2026 | The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall l... |
| CVE-2026-50214 | CRITICAL | 9.8 | 0.2% | Jun 4, 2026 | The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary... |
| CVE-2026-4881 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being... |
| CVE-2026-49771 | HIGH | 7.6 | 0.2% | Jun 4, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Galler... |
| CVE-2026-49510 | MEDIUM | 6.1 | 0.1% | Jun 4, 2026 | Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Integer Attacks. This issue affects ... |
| CVE-2026-47320 | MEDIUM | 6.1 | 0.1% | Jun 4, 2026 | Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Mani... |
| CVE-2026-47319 | MEDIUM | 6.1 | 0.1% | Jun 4, 2026 | Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Excessive Allocation. T... |
| CVE-2026-47318 | MEDIUM | 6.1 | 0.1% | Jun 4, 2026 | Stack-based buffer overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rl... |
| CVE-2026-47306 | MEDIUM | 6.1 | 0.1% | Jun 4, 2026 | Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads. This iss... |
| CVE-2026-10800 | LOW | 3.6 | 0.1% | Jun 4, 2026 | A weakness has been identified in PaddlePaddle FastDeploy up to 2.4.1. Affected by this issue is the function hash_featu... |
| CVE-2026-10305 | MEDIUM | 6.1 | 0.1% | Jun 4, 2026 | Out-of-bounds read vulnerability in Samsung Open Source rlottie allows Overread Buffers. This issue affects rlottie: be... |
| CVE-2026-50213 | HIGH | 7.5 | 0.2% | Jun 4, 2026 | The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled b... |
| CVE-2026-50212 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user... |
| CVE-2026-50211 | CRITICAL | 9.8 | 0.3% | Jun 4, 2026 | Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious... |
| CVE-2026-50210 | HIGH | 7.5 | 0.2% | Jun 4, 2026 | The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to re... |
| CVE-2026-50209 | HIGH | 7.8 | 0.1% | Jun 4, 2026 | Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint addres... |
| CVE-2026-50208 | CRITICAL | 9.4 | 0.1% | Jun 4, 2026 | High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric enc... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now