2026 CVE Vulnerabilities
45,091 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-55892 | MEDIUM | 5.5 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0662, the dump_prefixes() function in src/spell.c walks a ... |
| CVE-2026-4522 | MEDIUM | 6.7 | 0.1% | Jun 25, 2026 | Missing authentication for critical function vulnerability in HYPR Passwordless on Windows allows Credentials Intercepti... |
| CVE-2026-48946 | MEDIUM | 6.3 | 0.2% | Jun 25, 2026 | The K2 frontend article-attachment upload path accepts files whose extension is `.php`, and Apache's standard mod_php ma... |
| CVE-2026-48945 | MEDIUM | 5.3 | 0.2% | Jun 25, 2026 | The K2 article gallery upload path accepts a zip/tar archive, extracts it under `/media/k2/galleries/<id>/`, and only re... |
| CVE-2026-48944 | MEDIUM | 6.5 | 0.3% | Jun 25, 2026 | The K2 frontend article-save handler accepts an `attachment[N][existing]` POST field that is concatenated with `JPATH_SI... |
| CVE-2026-48943 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | K2 ≤ 2.24 contains a mass-assignment defect in the K2 system user plugin `plg_user_k2`. A Registered Joomla user, by inc... |
| CVE-2026-48942 | MEDIUM | 6.1 | 0.1% | Jun 25, 2026 | K2 ≤ 2.26 renders the `#__k2_users.image` column directly into HTML `src` attributes via two distinct templates, in both... |
| CVE-2026-48941 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | The K2 frontend `item.checkin` task accepts an unauthenticated `sigProFolder` query parameter and uses it directly to ad... |
| CVE-2026-6432 | MEDIUM | 5.3 | 0.3% | Jun 25, 2026 | Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage. |
| CVE-2026-57587 | MEDIUM | 5.3 | 0.3% | Jun 25, 2026 | A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a... |
| CVE-2026-57536 | MEDIUM | 6.3 | 0.3% | Jun 25, 2026 | Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a success... |
| CVE-2026-57437 | MEDIUM | 5.3 | 0.3% | Jun 25, 2026 | Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::XPath... |
| CVE-2026-57436 | MEDIUM | 5.3 | 0.3% | Jun 25, 2026 | Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::Docum... |
| CVE-2026-49319 | MEDIUM | 6.9 | 0.2% | Jun 25, 2026 | Remote Keyless Entry System (RKES), using the 433 MHz key fob bearing FCC ID CWTR53R0 manufactured by ALPS ALPINE CO., L... |
| CVE-2026-13225 | MEDIUM | 5.3 | 0.3% | Jun 25, 2026 | Malicious HTML content could be injected into the email address of an order, which pretix showed without sanitization o... |
| CVE-2026-13223 | MEDIUM | 6.3 | 0.3% | Jun 25, 2026 | Our payment integration with Computop-based payment methods did not properly validate payment status responses. An atta... |
| CVE-2026-13222 | MEDIUM | 6.3 | 0.3% | Jun 25, 2026 | Our payment integration with Oppwa-based payment methods did not properly validate payment status responses. An attacke... |
| CVE-2026-57619 | MEDIUM | 6.5 | 0.3% | Jun 25, 2026 | Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions. |
| CVE-2026-57429 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | Contributor Broken Access Control in Slim SEO <= 4.6.2 versions. |
| CVE-2026-56050 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access ... |
| CVE-2026-56023 | MEDIUM | 5.4 | 0.2% | Jun 25, 2026 | Customer Broken Access Control in UPI QR Code Payment Gateway for WooCommerce <= 1.6.2 versions. |
| CVE-2026-56013 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions. |
| CVE-2026-52690 | MEDIUM | 5.9 | 0.4% | Jun 25, 2026 | Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of D... |
| CVE-2026-4526 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed global ZCL messages can trigger out-of-bounds reads in framework parsing logi... |
| CVE-2026-47154 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, a malformed GetProfileResponse message can trigger out-of-bounds reads while iterating ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now