2026 CVE Vulnerabilities
61,771 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-26824 | MEDIUM | 6.5 | 0.2% | Jun 3, 2026 | libxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the OLE container parser. Memory al... |
| CVE-2026-10766 | LOW | 3.6 | 0.1% | Jun 3, 2026 | A vulnerability has been found in mlrun up to 1.12.0-rc3. This impacts the function mlrun.utils.helpers.calculate_datafr... |
| CVE-2026-8889 | HIGH | 7.5 | 0.2% | Jun 3, 2026 | Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) an... |
| CVE-2026-8888 | HIGH | 7.5 | 0.4% | Jun 3, 2026 | Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as J... |
| CVE-2026-8881 | HIGH | 7.5 | 0.2% | Jun 3, 2026 | Version 3.0.7 of the Securly Chrome Extension uses EVP_BytesToKey key derivation with MD5 and a single iteration for AES... |
| CVE-2026-8879 | HIGH | 7.5 | 0.4% | Jun 3, 2026 | Version 3.0.7 of the Securly Chrome Extension dynamically registers content13.min.js as a content script via chrome.scri... |
| CVE-2026-8878 | HIGH | 7.5 | 0.2% | Jun 3, 2026 | Version 3.0.7 of the Securly Chrome Extension exposes multiple publicly accessible endpoints that allow unauthenticated ... |
| CVE-2026-8876 | HIGH | 7.3 | 0.2% | Jun 3, 2026 | Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in securly.min.js. These key... |
| CVE-2026-8874 | HIGH | 7.1 | 0.1% | Jun 3, 2026 | Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules ... |
| CVE-2026-7888 | HIGH | 8.4 | 0.2% | Jun 3, 2026 | Concrete CMS below 9.5.3 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and ... |
| CVE-2026-45702 | MEDIUM | 5.5 | 0.2% | Jun 3, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-45614 | MEDIUM | 4.7 | 0.1% | Jun 3, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-42840 | MEDIUM | 5.1 | 0.2% | Jun 3, 2026 | An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and... |
| CVE-2026-42839 | MEDIUM | 4.8 | 0.3% | Jun 3, 2026 | An authenticated ERPNext user with Item record edit permissions can persist arbitrary HTML/JavaScript in the item_name, ... |
| CVE-2026-26379 | MEDIUM | 6.5 | 0.2% | Jun 3, 2026 | Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configura... |
| CVE-2026-26378 | MEDIUM | 5.4 | 0.3% | Jun 3, 2026 | Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file ... |
| CVE-2026-46273 | HIGH | 8.6 | 0.4% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packets with small MSS So... |
| CVE-2026-46272 | MEDIUM | 4.7 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: coresight: tmc-etr: Fix race condition between sysf... |
| CVE-2026-46271 | HIGH | 7.8 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: do WoW offloads only on primary link ... |
| CVE-2026-46270 | HIGH | 8.4 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: power: supply: rt9455: Fix use-after-free in power_... |
| CVE-2026-46269 | MEDIUM | 5.5 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: canaan: k230: Fix NULL pointer dereference... |
| CVE-2026-46268 | MEDIUM | 5.5 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: PCI/P2PDMA: Fix p2pmem_alloc_mmap() warning conditi... |
| CVE-2026-46267 | HIGH | 7.8 | 0.1% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfc: hci: shdlc: Stop timers and work before freein... |
| CVE-2026-46266 | CRITICAL | 9.1 | 0.3% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets using IPPROTO_RAW MUST drop incom... |
| CVE-2026-46265 | HIGH | 7.5 | 0.4% | Jun 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix WQ_MEM_RECLAIM warning When sunrpc i... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now