2026 CVE Vulnerabilities
61,772 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41412 | MEDIUM | 4.9 | 0.3% | Jun 2, 2026 | alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to versio... |
| CVE-2026-40108 | HIGH | 7.1 | 0.3% | Jun 2, 2026 | GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XS... |
| CVE-2026-35482 | CRITICAL | 9.1 | 0.2% | Jun 2, 2026 | alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to versio... |
| CVE-2026-32625 | CRITICAL | 9.6 | 2.9% | Jun 2, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the M... |
| CVE-2026-31942 | HIGH | 7.1 | 0.2% | Jun 2, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.7.6, an In... |
| CVE-2026-27145 | MEDIUM | 6.5 | 0.6% | Jun 2, 2026 | (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN... |
| CVE-2026-25861 | HIGH | 8.2 | 0.2% | Jun 2, 2026 | QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attack... |
| CVE-2026-10719 | LOW | 1.8 | 0.1% | Jun 2, 2026 | Out of bounds write in openSeaChest’s --showSupportedFormats in Seagate’s openSeaChest v25.05.3 on all supported platfor... |
| CVE-2026-10718 | MEDIUM | 4.6 | 0.1% | Jun 2, 2026 | Out of bounds write in openSeaChest’s Trim/Unmap operation in Seagate’s openSeaChest v26.03.0 on all supported platforms... |
| CVE-2026-10717 | LOW | 1.8 | 0.1% | Jun 2, 2026 | Out of bounds write and reads in openSeaChest’s --showSCSIDefects in Seagate’s openSeaChest v25.05.3 on all supported pl... |
| CVE-2026-10688 | MEDIUM | 5.5 | 0.2% | Jun 2, 2026 | A vulnerability was determined in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. The impacted elem... |
| CVE-2026-10662 | MEDIUM | 6.3 | 0.2% | Jun 2, 2026 | A vulnerability was found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. The affected element i... |
| CVE-2026-8936 | HIGH | 8.2 | 0.1% | Jun 2, 2026 | Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container created deeply nested dire... |
| CVE-2026-42029 | — | — | — | Jun 2, 2026 | Rejected reason: This CVE is a duplicate of another CVE. |
| CVE-2026-35212 | MEDIUM | 6.1 | 0.1% | Jun 2, 2026 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Versions prior to 7... |
| CVE-2026-10661 | MEDIUM | 4.3 | 0.2% | Jun 2, 2026 | A vulnerability has been found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. Impacted is the f... |
| CVE-2026-10650 | MEDIUM | 5.5 | 0.4% | Jun 2, 2026 | A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of t... |
| CVE-2026-49448 | CRITICAL | 9.8 | 0.4% | Jun 2, 2026 | authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can... |
| CVE-2026-49443 | HIGH | 8.8 | 0.3% | Jun 2, 2026 | authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the... |
| CVE-2026-49144 | HIGH | 7.1 | 0.2% | Jun 2, 2026 | BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js ... |
| CVE-2026-49143 | HIGH | 8.8 | 0.4% | Jun 2, 2026 | BrowserStack Runner through 0.9.5 contains a remote code execution vulnerability in the /_log HTTP handler that allows u... |
| CVE-2026-47201 | HIGH | 8.5 | 0.2% | Jun 2, 2026 | authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Sou... |
| CVE-2026-45289 | MEDIUM | 5.3 | 0.1% | Jun 2, 2026 | CloudburstMC Protocol is a protocol library for Minecraft Bedrock Edition. Prior to version 3.0.0.Beta12-20260420.182526... |
| CVE-2026-42849 | CRITICAL | 9.3 | 0.4% | Jun 2, 2026 | authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, due to the implementation of st... |
| CVE-2026-41569 | MEDIUM | 6.1 | 0.2% | Jun 2, 2026 | authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now