2026 CVE Vulnerabilities
61,773 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0018 | MEDIUM | 5.5 | 0.1% | Jun 1, 2026 | In multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of service due to impro... |
| CVE-2026-0016 | LOW | 3.3 | 0.1% | Jun 1, 2026 | In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings acro... |
| CVE-2026-0009 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalat... |
| CVE-2026-5419 | LOW | 3.7 | 0.4% | Jun 1, 2026 | A flaw was found in gnutls. The PKCS#7 padding check, performed during decryption, was not constant-time. This timing si... |
| CVE-2026-49433 | MEDIUM | 5 | 0.1% | Jun 1, 2026 | The DeepAI endpoint 'https://api.deepai.org/change_user_email' accepts POST requests without any CSRF protection. If an ... |
| CVE-2026-49140 | MEDIUM | 5.3 | 0.3% | Jun 1, 2026 | Nanobot prior to version 0.2.1 contains a denial of service vulnerability in the Matrix channel media download handler t... |
| CVE-2026-49139 | HIGH | 7 | 0.4% | Jun 1, 2026 | Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handl... |
| CVE-2026-49138 | MEDIUM | 5.3 | 0.3% | Jun 1, 2026 | Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the web_fetch tool that allows re... |
| CVE-2026-49136 | HIGH | 8.7 | 0.4% | Jun 1, 2026 | Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversal vulnerability in the generate_image() ... |
| CVE-2026-49135 | HIGH | 7.2 | 0.1% | Jun 1, 2026 | CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to acces... |
| CVE-2026-49134 | HIGH | 7.5 | 0.3% | Jun 1, 2026 | CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CLI installer that allows local attackers ... |
| CVE-2026-37234 | HIGH | 8.2 | 0.3% | Jun 1, 2026 | FlexRIC v2.0.0 allows a single SCTP connection to bind multiple xapp_ids by sending multiple E42_SETUP_REQUESTs. On disc... |
| CVE-2026-24751 | HIGH | 8.2 | 0.3% | Jun 1, 2026 | Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Dat... |
| CVE-2026-10289 | MEDIUM | 4.3 | 0.3% | Jun 1, 2026 | A security flaw has been discovered in code-projects Hotel and Tourism Reservation System 1.0. Impacted is an unknown fu... |
| CVE-2026-10288 | HIGH | 7.3 | 0.5% | Jun 1, 2026 | A vulnerability was identified in code-projects Hotel and Tourism Reservation System 1.0. This issue affects the functio... |
| CVE-2026-10287 | HIGH | 7.3 | 0.3% | Jun 1, 2026 | A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. This vulnerability affects the function get... |
| CVE-2026-10286 | MEDIUM | 6.3 | 0.2% | Jun 1, 2026 | A vulnerability was found in CodeAstro Payroll System 1.0. This affects an unknown part of the file /home_employee.php. ... |
| CVE-2026-10285 | MEDIUM | 5.4 | 0.2% | Jun 1, 2026 | A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the functi... |
| CVE-2026-10284 | MEDIUM | 5.4 | 0.2% | Jun 1, 2026 | A flaw has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this vulnerability is the functio... |
| CVE-2026-9614 | HIGH | 8.8 | 1.4% | Jun 1, 2026 | An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticate... |
| CVE-2026-9330 | HIGH | 8.5 | 0.5% | Jun 1, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deseria... |
| CVE-2026-9319 | CRITICAL | 9 | 0.5% | Jun 1, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of... |
| CVE-2026-9311 | CRITICAL | 9 | 0.5% | Jun 1, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security co... |
| CVE-2026-8644 | CRITICAL | 9.1 | 0.3% | Jun 1, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing. |
| CVE-2026-7770 | HIGH | 8.8 | 0.4% | Jun 1, 2026 | IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now