2026 CVE Vulnerabilities
61,772 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42654 | HIGH | 7.1 | 0.2% | Jun 2, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce allows... |
| CVE-2026-40780 | HIGH | 7.5 | 0.3% | Jun 2, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Liquid Web / StellarWP BookIt allows Password ... |
| CVE-2026-40619 | HIGH | 7.8 | 0.1% | Jun 2, 2026 | A high security vulnerability affecting Security Center main server installations has been identified. It could allow an... |
| CVE-2026-38978 | MEDIUM | 5.3 | 0.3% | Jun 2, 2026 | transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths. |
| CVE-2026-35718 | MEDIUM | 6.5 | 0.7% | Jun 2, 2026 | A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allow... |
| CVE-2026-35716 | MEDIUM | 6.3 | 0.3% | Jun 2, 2026 | A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authe... |
| CVE-2026-34460 | MEDIUM | 5.4 | 0.1% | Jun 2, 2026 | NamelessMC is website software for Minecraft servers. In versions 2.2.4 and prior, the OAuth callback handling does not ... |
| CVE-2026-33398 | HIGH | 7.1 | 0.2% | Jun 2, 2026 | NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/pages/forum/get_quotes.php` only ... |
| CVE-2026-30652 | HIGH | 8.8 | 0.5% | Jun 2, 2026 | A remote buffer overflow vulnerability exists in the /cgi-bin/dido/setdo.cgi endpoint of the admin interface of Vivotek ... |
| CVE-2026-30650 | HIGH | 8.8 | 0.6% | Jun 2, 2026 | A post-authentication remote buffer overflow vulnerability exists in the /cgi-bin/admin/eventtask.cgi endpoint of the ad... |
| CVE-2026-30649 | HIGH | 7.3 | 0.4% | Jun 2, 2026 | Buffer Overflow vulnerability in VIVOTEK INC FD8136-VVTK-0300a allows a remote attacker to execute arbitrary code via th... |
| CVE-2026-10629 | HIGH | 7.4 | 0.2% | Jun 2, 2026 | SIP signaling stack in Verizon IMS (unspecified version) implements SIP signaling without IPsec integrity protection (mi... |
| CVE-2026-10591 | HIGH | 8.8 | 0.4% | Jun 2, 2026 | Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remot... |
| CVE-2026-10047 | HIGH | 7.8 | 0.1% | Jun 2, 2026 | The Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the real-mode hook handler... |
| CVE-2026-10046 | HIGH | 7.8 | 0.1% | Jun 2, 2026 | Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the BIOS INT 0x15 / E820 memor... |
| CVE-2026-9844 | HIGH | 8.8 | 0.2% | Jun 2, 2026 | Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface mo... |
| CVE-2026-7313 | MEDIUM | 4.9 | 0.3% | Jun 2, 2026 | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 ... |
| CVE-2026-7312 | HIGH | 7.5 | 0.4% | Jun 2, 2026 | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152... |
| CVE-2026-7201 | HIGH | 8.8 | 0.3% | Jun 2, 2026 | CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441... |
| CVE-2026-7198 | CRITICAL | 9.8 | 0.4% | Jun 2, 2026 | CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unaut... |
| CVE-2026-7195 | HIGH | 8.1 | 0.5% | Jun 2, 2026 | CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152,... |
| CVE-2026-49782 | MEDIUM | 5.4 | 0.1% | Jun 2, 2026 | Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Acce... |
| CVE-2026-43965 | MEDIUM | 5.6 | 0.2% | Jun 2, 2026 | Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/pa... |
| CVE-2026-42795 | MEDIUM | 5.1 | 0.1% | Jun 2, 2026 | Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in th... |
| CVE-2026-41918 | MEDIUM | 5.9 | 0.2% | Jun 2, 2026 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applicatio... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now