2026 CVE Vulnerabilities
43,246 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12823 | LOW | 3.3 | 0.1% | Jun 22, 2026 | A security flaw has been discovered in Browserbase Skills up to 20260526. This impacts an unknown function of the compon... |
| CVE-2026-12812 | LOW | 3.5 | 0.2% | Jun 21, 2026 | A security vulnerability has been detected in Radware Cyber Controller up to 10.11.0. This affects an unknown part of th... |
| CVE-2026-56355 | LOW | 3.7 | 0.3% | Jun 20, 2026 | GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization. |
| CVE-2026-56325 | LOW | 3.1 | 0.2% | Jun 20, 2026 | Capgo before 12.128.2 uses ILIKE pattern matching instead of exact matching for app_id lookup in the preview subdomain r... |
| CVE-2026-48794 | LOW | 1.3 | 0.3% | Jun 19, 2026 | Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-o... |
| CVE-2026-47203 | LOW | 2.9 | 0.3% | Jun 19, 2026 | Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-o... |
| CVE-2026-49358 | LOW | 3 | 0.1% | Jun 19, 2026 | PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `AbstractGene... |
| CVE-2026-8668 | LOW | 2.3 | 0.2% | Jun 18, 2026 | A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues. Q... |
| CVE-2026-48617 | LOW | 1.8 | 0.2% | Jun 18, 2026 | A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This... |
| CVE-2026-40457 | LOW | 2.1 | 0.3% | Jun 18, 2026 | A Reflected Cross-Site Scripting (XSS) vulnerability exists in LMS (LAN Management System) before commit 9c5651b in the ... |
| CVE-2026-12102 | LOW | 2.7 | 0.3% | Jun 18, 2026 | The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPre... |
| CVE-2026-50268 | LOW | 1.9 | 0.0% | Jun 17, 2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati... |
| CVE-2026-12567 | LOW | 2.2 | 0.1% | Jun 17, 2026 | The github_workflows module constructs local directory paths from user-controlled repository names without validating fo... |
| CVE-2026-12566 | LOW | 3.1 | 0.2% | Jun 17, 2026 | The docker_pull module uses the realm parameter from a Docker registry's WWW-Authenticate response header as the authent... |
| CVE-2026-6733 | LOW | 3.7 | 0.2% | Jun 17, 2026 | Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-con... |
| CVE-2026-39199 | LOW | 2.9 | 0.1% | Jun 17, 2026 | snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file. |
| CVE-2026-11525 | LOW | 3.7 | 0.2% | Jun 17, 2026 | Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or No... |
| CVE-2026-12458 | LOW | 3.1 | 0.2% | Jun 17, 2026 | Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinc... |
| CVE-2026-0057 | LOW | 3.3 | 0.1% | Jun 17, 2026 | In Contacts Provider, there is a possible way to access an incoming call's phone number and associated metadata due to a... |
| CVE-2026-46977 | LOW | 3.2 | 0.2% | Jun 17, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v... |
| CVE-2026-46874 | LOW | 3.2 | 0.1% | Jun 17, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th... |
| CVE-2026-46816 | LOW | 3.2 | 0.2% | Jun 17, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v... |
| CVE-2026-46815 | LOW | 3.2 | 0.2% | Jun 17, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v... |
| CVE-2026-0158 | LOW | 3.3 | 0.1% | Jun 16, 2026 | In Camera, there is a possible unauthorized way to access photos due to a missing permission check. This could lead to l... |
| CVE-2026-0145 | LOW | 3.3 | 0.1% | Jun 16, 2026 | In keymint, there is a possible Permission Bypass due to a logic error in the code. This could lead to local information... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now