2026 CVE Vulnerabilities
61,786 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24751 | HIGH | 8.2 | 0.3% | Jun 1, 2026 | Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Dat... |
| CVE-2026-10289 | MEDIUM | 4.3 | 0.3% | Jun 1, 2026 | A security flaw has been discovered in code-projects Hotel and Tourism Reservation System 1.0. Impacted is an unknown fu... |
| CVE-2026-10288 | HIGH | 7.3 | 0.5% | Jun 1, 2026 | A vulnerability was identified in code-projects Hotel and Tourism Reservation System 1.0. This issue affects the functio... |
| CVE-2026-10287 | HIGH | 7.3 | 0.3% | Jun 1, 2026 | A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. This vulnerability affects the function get... |
| CVE-2026-10286 | MEDIUM | 6.3 | 0.2% | Jun 1, 2026 | A vulnerability was found in CodeAstro Payroll System 1.0. This affects an unknown part of the file /home_employee.php. ... |
| CVE-2026-10285 | MEDIUM | 5.4 | 0.2% | Jun 1, 2026 | A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the functi... |
| CVE-2026-10284 | MEDIUM | 5.4 | 0.2% | Jun 1, 2026 | A flaw has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this vulnerability is the functio... |
| CVE-2026-9614 | HIGH | 8.8 | 1.4% | Jun 1, 2026 | An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticate... |
| CVE-2026-9330 | HIGH | 8.5 | 0.5% | Jun 1, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deseria... |
| CVE-2026-9319 | CRITICAL | 9 | 0.5% | Jun 1, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of... |
| CVE-2026-9311 | CRITICAL | 9 | 0.5% | Jun 1, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security co... |
| CVE-2026-8644 | CRITICAL | 9.1 | 0.3% | Jun 1, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing. |
| CVE-2026-7770 | HIGH | 8.8 | 0.4% | Jun 1, 2026 | IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution ... |
| CVE-2026-49121 | CRITICAL | 9.8 | 1.1% | Jun 1, 2026 | AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the ... |
| CVE-2026-47294 | HIGH | 8 | 0.6% | Jun 1, 2026 | Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoin... |
| CVE-2026-45810 | MEDIUM | 6.8 | 0.3% | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, ... |
| CVE-2026-45729 | MEDIUM | 4.3 | 0.2% | Jun 1, 2026 | Thor Vector Graphics (ThorVG) is a production-ready vector graphics engine. Prior to version 1.0.5, a null pointer deref... |
| CVE-2026-45727 | HIGH | 8.8 | 0.5% | Jun 1, 2026 | CloakBrowser is a tool to bypass bot detection tests. Prior to version 0.3.28, the cloakserve CDP multiplexer uses the u... |
| CVE-2026-45722 | HIGH | 7.1 | 0.3% | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and 1.0.0 to before 1.0... |
| CVE-2026-45691 | MEDIUM | 5.9 | 0.3% | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, a... |
| CVE-2026-45690 | MEDIUM | 5.9 | 0.3% | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, a... |
| CVE-2026-45545 | HIGH | 8.2 | 0.3% | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10,... |
| CVE-2026-45544 | MEDIUM | 4.3 | 0.2% | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter ... |
| CVE-2026-45543 | MEDIUM | 5.3 | 0.3% | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collab... |
| CVE-2026-45302 | HIGH | 8.2 | 0.3% | Jun 1, 2026 | parse-nested-form-data is a tiny node module for parsing FormData by name into objects and arrays. Prior to version 1.0.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now