2026 CVE Vulnerabilities
45,065 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13455 | MEDIUM | 4.3 | 0.1% | Jun 30, 2026 | PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() ... |
| CVE-2026-4360 | MEDIUM | 5.3 | 0.3% | Jun 30, 2026 | In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected sy... |
| CVE-2026-48192 | MEDIUM | 6.8 | 0.2% | Jun 30, 2026 | A vulnerability has been identified in Mendix Studio Pro 10.11 (All versions), Mendix Studio Pro 10.12 (All versions), M... |
| CVE-2026-44947 | MEDIUM | 6.9 | 0.2% | Jun 30, 2026 | A missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher versions 2.13.0 up to 2.13.... |
| CVE-2026-27956 | MEDIUM | 4.3 | — | Jun 30, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-27955 | MEDIUM | 6.6 | — | Jun 30, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-27883 | MEDIUM | 5 | 0.2% | Jun 30, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-27882 | MEDIUM | 4.8 | — | Jun 30, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-27881 | MEDIUM | 5 | — | Jun 30, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-35098 | MEDIUM | 6.9 | — | Jun 30, 2026 | KTM System e-BOK does not implement any limit or timeout on consecutive login attempts, allowing an attacker to perform ... |
| CVE-2026-35097 | MEDIUM | 6.9 | — | Jun 30, 2026 | KTM System e-BOK enforces a maximum password length of six numeric digits and does not permit the use of any alphabetic,... |
| CVE-2026-35096 | MEDIUM | 5.1 | — | Jun 30, 2026 | KTM System e-BOK is vulnerable to Cross‑Site Request Forgery (CSRF) in both the email-change and password-change functio... |
| CVE-2026-35095 | MEDIUM | 4.8 | — | Jun 30, 2026 | KTM System e-BOK allows the session identifier to be set by the client prior to authentication. If a cookie with a valid... |
| CVE-2026-14178 | MEDIUM | 5.9 | — | Jun 30, 2026 | openGauss 在处理带 NLS 参数的 to_timestamp 调用时,to_timestamp_with_fmt_nls() 会将 nls_fmt_str 保存到 u_sess->parser_cxt.nls_fmt_str。在 ... |
| CVE-2026-8403 | MEDIUM | 6.1 | — | Jun 30, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Eksagate Electroni... |
| CVE-2026-4629 | MEDIUM | 6.5 | 0.3% | Jun 30, 2026 | A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability b... |
| CVE-2026-14209 | MEDIUM | 4.3 | 0.2% | Jun 30, 2026 | A vulnerability was discovered in Keycloak's Admin UI extension that allows certain administrative users to bypass secur... |
| CVE-2026-12388 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user informati... |
| CVE-2026-57082 | MEDIUM | 5.9 | 0.2% | Jun 30, 2026 | Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG... |
| CVE-2026-57079 | MEDIUM | 5.3 | 0.3% | Jun 30, 2026 | Net::BitTorrent versions before 2.1.0 for Perl write files outside the download directory via path traversal in peer-sup... |
| CVE-2026-53692 | MEDIUM | 5.9 | — | Jun 30, 2026 | Redeight CMS version 1.0 uses the MD5 algorithm without a salt to store user passwords. Because MD5 is a cryptographical... |
| CVE-2026-52760 | MEDIUM | 6.1 | 0.3% | Jun 30, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, A... |
| CVE-2026-13316 | MEDIUM | 4.4 | 0.1% | Jun 30, 2026 | A flaw has been found in foreman when HTTP parameters are modified in http_proxies_controller and http_proxy files. Atta... |
| CVE-2026-6954 | MEDIUM | 5.1 | 0.4% | Jun 30, 2026 | Cross-Site Scripting (XSS) vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to... |
| CVE-2026-6953 | MEDIUM | 5.1 | 0.4% | Jun 30, 2026 | HTML injection vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to send an ema... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now