2026 CVE Vulnerabilities
61,772 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-37462 | HIGH | 7.5 | 0.3% | Jun 3, 2026 | An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a... |
| CVE-2026-36748 | CRITICAL | 9 | 0.3% | Jun 3, 2026 | RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile. |
| CVE-2026-36576 | CRITICAL | 9.8 | 1.5% | Jun 3, 2026 | An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 al... |
| CVE-2026-36574 | HIGH | 7.8 | 0.1% | Jun 3, 2026 | A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and e... |
| CVE-2026-8404 | MEDIUM | 5.3 | 0.3% | Jun 3, 2026 | An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware... |
| CVE-2026-7666 | LOW | 3.1 | 0.1% | Jun 3, 2026 | An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` ... |
| CVE-2026-6873 | MEDIUM | 4.3 | 0.2% | Jun 3, 2026 | An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in... |
| CVE-2026-5241 | CRITICAL | 9.6 | 0.5% | Jun 3, 2026 | A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-control... |
| CVE-2026-48587 | MEDIUM | 5.3 | 0.4% | Jun 3, 2026 | An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Djan... |
| CVE-2026-47325 | MEDIUM | 6.9 | 0.2% | Jun 3, 2026 | ProjectsAndPrograms school-management-system uses predictable credentials by generating student's and teacher's password... |
| CVE-2026-47324 | MEDIUM | 5.1 | 0.3% | Jun 3, 2026 | ProjectsAndPrograms school-management-system is vulnerable to Stored Cross‑Site Scripting (XSS) in multiple attributes o... |
| CVE-2026-44546 | MEDIUM | 5.3 | 0.2% | Jun 3, 2026 | daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket... |
| CVE-2026-44545 | HIGH | 7.5 | 0.3% | Jun 3, 2026 | daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Beca... |
| CVE-2026-37460 | HIGH | 7.5 | 0.3% | Jun 3, 2026 | Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 all... |
| CVE-2026-35193 | LOW | 3.1 | 0.4% | Jun 3, 2026 | An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware... |
| CVE-2026-10729 | LOW | 1.2 | 0.2% | Jun 3, 2026 | An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists i... |
| CVE-2026-35085 | HIGH | 8.8 | 0.5% | Jun 3, 2026 | A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system acces... |
| CVE-2026-35084 | HIGH | 8.8 | 0.5% | Jun 3, 2026 | A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access ... |
| CVE-2026-35083 | HIGH | 8.8 | 0.5% | Jun 3, 2026 | A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root. |
| CVE-2026-35082 | HIGH | 8.8 | 0.5% | Jun 3, 2026 | The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient... |
| CVE-2026-35081 | HIGH | 8.1 | 0.4% | Jun 3, 2026 | The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficien... |
| CVE-2026-35080 | HIGH | 8.1 | 0.4% | Jun 3, 2026 | The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insuffic... |
| CVE-2026-35079 | HIGH | 8.1 | 0.4% | Jun 3, 2026 | The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient... |
| CVE-2026-35078 | HIGH | 8.1 | 0.4% | Jun 3, 2026 | The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficien... |
| CVE-2026-35077 | HIGH | 8.1 | 0.4% | Jun 3, 2026 | The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insuffi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now