2026 CVE Vulnerabilities
45,066 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12610 | MEDIUM | 6.4 | 0.2% | Jun 30, 2026 | A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free v... |
| CVE-2026-45822 | MEDIUM | 6.6 | 0.3% | Jun 30, 2026 | decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' produci... |
| CVE-2026-9576 | MEDIUM | 4.9 | 0.1% | Jun 30, 2026 | The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting a... |
| CVE-2026-56809 | MEDIUM | 6.1 | 0.2% | Jun 30, 2026 | Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cr... |
| CVE-2026-11581 | MEDIUM | 5.9 | 0.2% | Jun 30, 2026 | The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form field's ca... |
| CVE-2026-8944 | MEDIUM | 4.3 | 0.1% | Jun 30, 2026 | The Plugin for Google Analytics by IO technologies plugin for WordPress is vulnerable to Cross-Site Request Forgery in v... |
| CVE-2026-12560 | MEDIUM | 4.4 | 0.2% | Jun 30, 2026 | The Editorial Rating – Product Review & Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting ... |
| CVE-2026-12349 | MEDIUM | 5.3 | 0.2% | Jun 30, 2026 | The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in ... |
| CVE-2026-11367 | MEDIUM | 6.5 | 0.5% | Jun 30, 2026 | The PixMagix – WordPress Image Editor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, a... |
| CVE-2026-14160 | MEDIUM | 5.9 | 0.1% | Jun 30, 2026 | Time-of-check time-of-use (TOCTOU) race condition vulnerability in Samsung Open Source Escargot allows Leveraging Race C... |
| CVE-2026-12114 | MEDIUM | 4.4 | 0.2% | Jun 30, 2026 | The Team Members – Multi Language Supported Team Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2026-7656 | MEDIUM | 6.8 | 0.3% | Jun 29, 2026 | The IPv6 Neighbor Discovery handlers in subsys/net/ip/ipv6_nbr.c (handle_ra_input, handle_ns_input, handle_na_input) use... |
| CVE-2026-10648 | MEDIUM | 5.5 | 0.1% | Jun 29, 2026 | mcumgr_serial_process_frag() in subsys/mgmt/mcumgr/transport/src/serial_util.c calls net_buf_reset() on the result of sm... |
| CVE-2026-57997 | MEDIUM | 5.4 | 0.1% | Jun 29, 2026 | Strapi users-permissions plugin fails to restrict JWT algorithms when plugin::users-permissions.jwt.algorithm is not exp... |
| CVE-2026-10647 | MEDIUM | 5.3 | 0.2% | Jun 29, 2026 | The USB CDC-NCM device class (subsys/usb/device_next/class/usbd_cdc_ncm.c) ignores the return value of usbd_ep_enqueue()... |
| CVE-2026-55956 | MEDIUM | 6.5 | 0.2% | Jun 29, 2026 | Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ig... |
| CVE-2026-55955 | MEDIUM | 6.5 | 0.3% | Jun 29, 2026 | Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the ... |
| CVE-2026-50229 | MEDIUM | 6.1 | 0.2% | Jun 29, 2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example ... |
| CVE-2026-54889 | MEDIUM | 5.1 | 0.3% | Jun 29, 2026 | Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in leandrocp mdex allows cross-site scri... |
| CVE-2026-54888 | MEDIUM | 6.9 | 0.2% | Jun 29, 2026 | Uncontrolled Recursion vulnerability in leandrocp mdex allows denial of service via deeply nested Markdown input. mdex ... |
| CVE-2026-53429 | MEDIUM | 6.9 | 0.1% | Jun 29, 2026 | Missing Release of Memory after Effective Lifetime vulnerability in leandrocp mdex and mdex_native allows an attacker wh... |
| CVE-2026-43746 | MEDIUM | 6.5 | 0.2% | Jun 29, 2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 a... |
| CVE-2026-43745 | MEDIUM | 6.5 | 0.6% | Jun 29, 2026 | An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.... |
| CVE-2026-43743 | MEDIUM | 4.7 | 0.1% | Jun 29, 2026 | A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS ... |
| CVE-2026-43742 | MEDIUM | 6.5 | 0.3% | Jun 29, 2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now