2026 CVE Vulnerabilities
61,772 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39555 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection. This issue affects Askk... |
| CVE-2026-39553 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-39552 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-35717 | MEDIUM | 6.3 | 0.3% | Jun 2, 2026 | A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows auth... |
| CVE-2026-32685 | MEDIUM | 4.6 | 0.2% | Jun 2, 2026 | Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file read and file write... |
| CVE-2026-32250 | MEDIUM | 4.3 | 0.2% | Jun 2, 2026 | NamelessMC is website software for Minecraft servers. A Reflected Cross-Site Scripting (XSS) vulnerability was discovere... |
| CVE-2026-28116 | MEDIUM | 5.9 | 0.1% | Jun 2, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emilia Projects Pr... |
| CVE-2026-27351 | MEDIUM | 5.4 | 0.2% | Jun 2, 2026 | Missing Authorization vulnerability in Sekander Badsha Crew HRM allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2026-10622 | HIGH | 8.2 | 0.4% | Jun 2, 2026 | Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to access privileged fun... |
| CVE-2026-10621 | HIGH | 7.5 | 0.4% | Jun 2, 2026 | Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archi... |
| CVE-2026-10611 | CRITICAL | 10 | 0.4% | Jun 2, 2026 | An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In... |
| CVE-2026-8993 | MEDIUM | 6.5 | 0.2% | Jun 2, 2026 | D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Applicatio... |
| CVE-2026-42685 | HIGH | 7.1 | 0.1% | Jun 2, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad WP Job Porta... |
| CVE-2026-42684 | CRITICAL | 9.3 | 0.3% | Jun 2, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ahmad WP Job Porta... |
| CVE-2026-42670 | HIGH | 7.5 | 0.3% | Jun 2, 2026 | Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations allows Exploitin... |
| CVE-2026-42669 | HIGH | 7.5 | 0.2% | Jun 2, 2026 | Missing Authorization vulnerability in EventPrime allows Exploiting Incorrectly Configured Access Control Security Level... |
| CVE-2026-39551 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. This issue affects Töbe... |
| CVE-2026-39550 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection. This issue affects A... |
| CVE-2026-5422 | HIGH | 8.1 | 0.4% | Jun 2, 2026 | A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check... |
| CVE-2026-5191 | MEDIUM | 5.4 | 0.1% | Jun 2, 2026 | The Tiled Gallery Carousel Without JetPack plugin for WordPress is vulnerable to stored cross-site scripting via the 'da... |
| CVE-2026-46718 | MEDIUM | 6.5 | 0.4% | Jun 2, 2026 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite. Thi... |
| CVE-2026-41115 | MEDIUM | 4.3 | 0.3% | Jun 2, 2026 | An improper authorization vulnerability has been identified in Apache Kafka. The implementation of the CONSUMER_GROUP_D... |
| CVE-2026-34907 | MEDIUM | 5.1 | 0.3% | Jun 2, 2026 | Wirtualna Uczelnia is vulnerable to Reflected Cross‑Site Scripting (XSS) due to insecure handling of the locale paramete... |
| CVE-2026-34906 | CRITICAL | 9.3 | 0.6% | Jun 2, 2026 | Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to perform Remote Code Ex... |
| CVE-2026-10549 | MEDIUM | 5.3 | 0.3% | Jun 2, 2026 | LDAP filter injection vulnerability in Yandex Database prior to 25.3.1.25 allows a remote attacker with valid LDAP crede... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now