2026 CVE Vulnerabilities
61,772 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35076 | HIGH | 8.1 | 0.4% | Jun 3, 2026 | The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insuffici... |
| CVE-2026-35075 | CRITICAL | 9.8 | 0.5% | Jun 3, 2026 | An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full a... |
| CVE-2026-10722 | MEDIUM | 5.5 | 0.2% | Jun 3, 2026 | A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go... |
| CVE-2026-47065 | CRITICAL | 9.8 | 0.5% | Jun 3, 2026 | ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Ful... |
| CVE-2026-41032 | HIGH | 7.5 | 0.3% | Jun 3, 2026 | It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some... |
| CVE-2026-4035 | HIGH | 7.7 | 0.4% | Jun 3, 2026 | A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gatew... |
| CVE-2026-5078 | MEDIUM | 5.3 | 0.2% | Jun 3, 2026 | Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization reque... |
| CVE-2026-50052 | LOW | 2.3 | 0.3% | Jun 3, 2026 | In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to l... |
| CVE-2026-50031 | HIGH | 7.5 | 0.4% | Jun 3, 2026 | ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Manag... |
| CVE-2026-10705 | LOW | 3.1 | 0.3% | Jun 3, 2026 | A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/datafram... |
| CVE-2026-10704 | HIGH | 7.3 | 0.3% | Jun 3, 2026 | A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the func... |
| CVE-2026-10703 | MEDIUM | 6.3 | 0.2% | Jun 3, 2026 | A security vulnerability has been detected in EIPStackGroup OpENer up to 2.3.0. Affected is the function CreateMessageRo... |
| CVE-2026-9516 | HIGH | 7.5 | 0.4% | Jun 3, 2026 | Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter... |
| CVE-2026-9334 | HIGH | 7.3 | 0.3% | Jun 3, 2026 | Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref i... |
| CVE-2026-10694 | HIGH | 7.3 | 0.3% | Jun 3, 2026 | A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function i... |
| CVE-2026-10693 | MEDIUM | 6.3 | 0.2% | Jun 3, 2026 | A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Affected by this vulner... |
| CVE-2026-9732 | MEDIUM | 4.3 | 0.1% | Jun 3, 2026 | The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forger... |
| CVE-2026-7421 | MEDIUM | 4.4 | 0.2% | Jun 3, 2026 | The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu... |
| CVE-2026-10692 | MEDIUM | 4.3 | 0.3% | Jun 3, 2026 | A weakness has been identified in johnhuang316 code-index-mcp up to 2.14.0. Affected is the function is_safe_regex_patte... |
| CVE-2026-10691 | MEDIUM | 4.3 | 0.4% | Jun 3, 2026 | A security flaw has been discovered in wonderwhy-er DesktopCommanderMCP up to 0.2.38. This impacts an unknown function o... |
| CVE-2026-10690 | MEDIUM | 6.3 | 0.2% | Jun 3, 2026 | A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of ... |
| CVE-2026-44654 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, a sha... |
| CVE-2026-44653 | MEDIUM | 6.5 | 0.3% | Jun 2, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, users... |
| CVE-2026-42507 | MEDIUM | 5.3 | 0.4% | Jun 2, 2026 | When returning errors, functions in the net/textproto package would include its input as part of the error. This might a... |
| CVE-2026-42504 | HIGH | 7.5 | 0.6% | Jun 2, 2026 | Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now