2026 CVE Vulnerabilities
45,091 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57914 | MEDIUM | 6.5 | — | Jun 26, 2026 | By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow ... |
| CVE-2026-57620 | MEDIUM | 6.5 | — | Jun 26, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclu... |
| CVE-2026-57473 | MEDIUM | 5.8 | — | Jun 26, 2026 | A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911)... |
| CVE-2026-6658 | MEDIUM | 5.4 | 0.2% | Jun 26, 2026 | A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows for Cross-site Scripting (XSS) via unsanitized `text/vnd.... |
| CVE-2026-1869 | MEDIUM | 6.5 | 0.2% | Jun 26, 2026 | The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom U... |
| CVE-2026-8380 | MEDIUM | 6.5 | 0.2% | Jun 26, 2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post... |
| CVE-2026-8661 | MEDIUM | 4.8 | 0.3% | Jun 26, 2026 | Server-Side Request Forgery in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin on Linux in versions ... |
| CVE-2026-50745 | MEDIUM | 6.1 | 0.1% | Jun 26, 2026 | A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script w... |
| CVE-2026-50744 | MEDIUM | 4.3 | 0.2% | Jun 26, 2026 | A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login me... |
| CVE-2026-50742 | MEDIUM | 5.4 | 0.1% | Jun 26, 2026 | A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revi... |
| CVE-2026-50740 | MEDIUM | 5.4 | 0.2% | Jun 26, 2026 | A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and ea... |
| CVE-2026-50739 | MEDIUM | 4.3 | 0.2% | Jun 26, 2026 | A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation o... |
| CVE-2026-48934 | MEDIUM | 4.3 | 0.3% | Jun 26, 2026 | A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability ... |
| CVE-2026-48928 | MEDIUM | 5.4 | 0.2% | Jun 26, 2026 | A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulne... |
| CVE-2026-48618 | MEDIUM | 6.5 | 3.2% | Jun 26, 2026 | A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth ... |
| CVE-2026-13226 | MEDIUM | 6.5 | 0.3% | Jun 26, 2026 | The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection ... |
| CVE-2026-43920 | MEDIUM | 6.9 | 0.5% | Jun 26, 2026 | FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patch... |
| CVE-2026-13318 | MEDIUM | 6.4 | 0.2% | Jun 26, 2026 | A server-side request forgery (SSRF) flaw was found in KubeVirt's virt-api port-forward handler. When processing a port-... |
| CVE-2026-13218 | MEDIUM | 4.2 | 0.1% | Jun 26, 2026 | A flaw was found in KubeVirt's virt-handler network cache handling. The WriteToCachedFile function writes data to a laun... |
| CVE-2026-13083 | MEDIUM | 6.9 | 0.2% | Jun 26, 2026 | A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper es... |
| CVE-2026-12993 | MEDIUM | 6.5 | 0.2% | Jun 26, 2026 | A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but d... |
| CVE-2026-40941 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import sign... |
| CVE-2026-40084 | MEDIUM | 6.5 | 0.3% | Jun 25, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Tra... |
| CVE-2026-40082 | MEDIUM | 5.4 | 0.2% | Jun 25, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have missing session_regen... |
| CVE-2026-40080 | MEDIUM | 6.1 | 0.1% | Jun 25, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Open Red... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now