2026 CVE Vulnerabilities
43,246 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48936 | LOW | 3.3 | 0.1% | Jun 26, 2026 | A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--... |
| CVE-2026-48935 | LOW | 3.3 | 0.1% | Jun 26, 2026 | A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with ... |
| CVE-2026-13322 | LOW | 3.8 | 0.1% | Jun 26, 2026 | A flaw was found in KubeVirt's downward metrics virtio-serial server. The server reads guest requests using textproto.Re... |
| CVE-2026-13350 | LOW | 2.3 | 0.2% | Jun 25, 2026 | Permissions where checked incorrectly during room creation, allowing attackers to create rooms of types they shouldn't b... |
| CVE-2026-48940 | LOW | 3.4 | 0.2% | Jun 25, 2026 | A Joomla user with K2 "create item" rights (Author tier by default) can submit an article whose `embedVideo` POST field ... |
| CVE-2026-57588 | LOW | 3.3 | 0.2% | Jun 25, 2026 | A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by ... |
| CVE-2026-57535 | LOW | 2.1 | 0.3% | Jun 25, 2026 | Content injected to PDF rendering contexts could, in many places, include HTML content including <img> tags. If the src ... |
| CVE-2026-57534 | LOW | 2.1 | 0.3% | Jun 25, 2026 | Malicious HTML content could be injected into the content of a page in the pretix-pages plugin. |
| CVE-2026-57533 | LOW | 2.1 | 0.2% | Jun 25, 2026 | Malicious HTML content could be injected into the page pretix shows when redirection to an untrusted page occurs. Since... |
| CVE-2026-57234 | LOW | 2.6 | 0.2% | Jun 25, 2026 | Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse opti... |
| CVE-2026-13314 | LOW | 2 | 0.3% | Jun 25, 2026 | Malicious HTML content could be injected into the content rendered by the pretix-digital plugin. |
| CVE-2026-12755 | LOW | 2.7 | 0.2% | Jun 25, 2026 | Improper input validation in the PAM AD discovery endpoints in Devolutions Server 2026.2.4.0 through 2026.2.7.0 allows ... |
| CVE-2026-42004 | LOW | 3.7 | 0.2% | Jun 25, 2026 | An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten ... |
| CVE-2026-40208 | LOW | 3.7 | 0.3% | Jun 25, 2026 | An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame... |
| CVE-2026-40011 | LOW | 3.7 | 0.2% | Jun 25, 2026 | An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a... |
| CVE-2026-56130 | LOW | 2 | 0.2% | Jun 25, 2026 | "Remember me" cookie age is not verified on the server. This potentially allows an attacker to intercept a valid cookie ... |
| CVE-2026-45188 | LOW | 2.4 | 0.2% | Jun 25, 2026 | Relative Path Traversal vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 1.0.0 through 2.15.0. ... |
| CVE-2026-3176 | LOW | 3.1 | 0.2% | Jun 25, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.... |
| CVE-2026-12635 | LOW | 3.1 | 0.2% | Jun 25, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.11.6, 19.0 before 19.0.3, and 1... |
| CVE-2026-0934 | LOW | 3.8 | 0.2% | Jun 25, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.... |
| CVE-2026-49979 | LOW | 2.7 | 0.3% | Jun 24, 2026 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.99, the POST /api/v1/admin/send... |
| CVE-2026-39894 | LOW | 2.5 | 0.1% | Jun 24, 2026 | Cacti is an open source performance and fault management framework. In versions 1.2.30 and below, the locale-dependent d... |
| CVE-2026-52796 | LOW | 3.5 | 0.3% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, specially crafted issue index pattern can cause a panic... |
| CVE-2026-49277 | LOW | 2.3 | 0.2% | Jun 24, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, ... |
| CVE-2026-45757 | LOW | 2.3 | 0.2% | Jun 24, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now