2026 CVE Vulnerabilities
45,066 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-28979 | MEDIUM | 6.5 | 0.3% | Jun 29, 2026 | An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 26.... |
| CVE-2026-13593 | MEDIUM | 6.5 | 0.2% | Jun 29, 2026 | CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away. The minif... |
| CVE-2026-53428 | MEDIUM | 6.9 | — | Jun 29, 2026 | Memory Allocation with Excessive Size Value vulnerability in leandrocp mdex allows an unauthenticated attacker to cause ... |
| CVE-2026-13757 | MEDIUM | 6.2 | 0.1% | Jun 29, 2026 | A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_mes... |
| CVE-2026-57958 | MEDIUM | 6.1 | — | Jun 29, 2026 | Mixpost through 2.6.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to e... |
| CVE-2026-57957 | MEDIUM | 4.7 | 0.3% | Jun 29, 2026 | Papermark through 0.22.0 contains a cross-origin resource sharing (CORS) misconfiguration vulnerability that allows unau... |
| CVE-2026-57956 | MEDIUM | 6.4 | 0.2% | Jun 29, 2026 | SigNoz before 0.133.0 contains a broken access control vulnerability that allows authenticated users to access other org... |
| CVE-2026-57954 | MEDIUM | 5.3 | 0.2% | Jun 29, 2026 | Elide through 7.1.17 fails to enforce @ReadPermission on client-supplied sort expressions in SortingImpl.getValidSorting... |
| CVE-2026-57953 | MEDIUM | 5.4 | 0.2% | Jun 29, 2026 | Mythic before 3.4.0.60 contains an authorization bypass vulnerability that allows authenticated spectator-role users to ... |
| CVE-2026-57952 | MEDIUM | 6.5 | 0.2% | Jun 29, 2026 | Mythic before 3.4.0.60 contains an authorization bypass vulnerability in four REST endpoints (c2profile_config_check_web... |
| CVE-2026-57946 | MEDIUM | 6.3 | 0.3% | Jun 29, 2026 | Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attacke... |
| CVE-2026-57945 | MEDIUM | 5.3 | 0.2% | Jun 29, 2026 | PhotoPrism before 260601-a7d098548 contains a broken access control vulnerability that allows authenticated non-admin us... |
| CVE-2026-57943 | MEDIUM | 6 | 0.2% | Jun 29, 2026 | LibrePhotos before 1.0.0 contains a broken object level authorization vulnerability in the SetPhotosShared endpoint that... |
| CVE-2026-57942 | MEDIUM | 6.9 | — | Jun 29, 2026 | LibreTranslate through 1.9.7, fixed in commit 397fd22, contains an IP spoofing vulnerability in the get_remote_address()... |
| CVE-2026-56781 | MEDIUM | 6.9 | 0.2% | Jun 29, 2026 | Teable before 2026-06-15T04-43-24Z.1912 contains an improper access control vulnerability that allows anonymous attacker... |
| CVE-2026-13591 | MEDIUM | 5 | — | Jun 29, 2026 | A weakness has been identified in DeepMyst Mysti 0.4.0. Affected is the function _isTrackedConversation of the file src/... |
| CVE-2026-13590 | MEDIUM | 5.6 | 0.4% | Jun 29, 2026 | A security flaw has been discovered in seladb PcapPlusPlus 25.05. This impacts the function pcpp::ModbusLayer::getLength... |
| CVE-2026-13589 | MEDIUM | 5.6 | — | Jun 29, 2026 | A vulnerability was identified in seladb PcapPlusPlus 25.05. This affects the function pcpp::TelnetLayer::getSubCommand ... |
| CVE-2026-13588 | MEDIUM | 5.6 | — | Jun 29, 2026 | A vulnerability was determined in seladb PcapPlusPlus 25.05. The impacted element is the function pcpp::SSLClientHelloMe... |
| CVE-2026-9105 | MEDIUM | 6.5 | 0.3% | Jun 29, 2026 | An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v... |
| CVE-2026-13750 | MEDIUM | 5.5 | 0.1% | Jun 29, 2026 | Insertion of sensitive information into log files in Snowflake CLI versions prior to 3.19 allowed plaintext credentials ... |
| CVE-2026-13748 | MEDIUM | 6.3 | 0.1% | Jun 29, 2026 | Improper restriction of file path resolution in Snowflake CLI versions prior to 3.19 allowed arbitrary local file conten... |
| CVE-2026-13746 | MEDIUM | 5.4 | 0.1% | Jun 29, 2026 | Improper neutralization of local CLI parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution... |
| CVE-2026-13742 | MEDIUM | 5.9 | — | Jun 29, 2026 | Honeywell IQ MultiAccess, all versions prior to and including version 28, contain an improper digital signature verifica... |
| CVE-2026-13581 | MEDIUM | 6.3 | 1.2% | Jun 29, 2026 | A vulnerability was detected in Edimax EW-7478APC 1.04. This vulnerability affects the function formStaDrvSetup of the f... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now