2026 CVE Vulnerabilities
43,253 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48011 | LOW | 3.7 | 0.2% | Jun 10, 2026 | Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the us... |
| CVE-2026-46668 | LOW | 2.3 | 0.3% | Jun 10, 2026 | SpiceDB is an open source database system for creating and managing security-critical application permissions. From vers... |
| CVE-2026-45380 | LOW | 3.6 | 0.1% | Jun 10, 2026 | bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4... |
| CVE-2026-50568 | LOW | 3.6 | 0.1% | Jun 10, 2026 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic... |
| CVE-2026-46497 | LOW | 2.3 | 0.3% | Jun 10, 2026 | Crawlee is a web scraping and browser automation library. From version 1.0.0 to before version 1.7.0, Crawlee is vulnera... |
| CVE-2026-11859 | LOW | 2 | 0.3% | Jun 10, 2026 | An HTML injection vulnerability in the "fetch links" email sent by Thinkst Applied Research Canarytokens, enabling Inter... |
| CVE-2026-9060 | LOW | 3.5 | 0.1% | Jun 10, 2026 | The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and o... |
| CVE-2026-29114 | LOW | 2.3 | 0.2% | Jun 10, 2026 | A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that ... |
| CVE-2026-48289 | LOW | 3.5 | 0.3% | Jun 9, 2026 | Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vuln... |
| CVE-2026-48288 | LOW | 3.5 | 0.4% | Jun 9, 2026 | Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vuln... |
| CVE-2026-45642 | LOW | 3.9 | 0.3% | Jun 9, 2026 | Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authori... |
| CVE-2026-45485 | LOW | 3.3 | 0.4% | Jun 9, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. |
| CVE-2026-45466 | LOW | 3.3 | 0.4% | Jun 9, 2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
| CVE-2026-45459 | LOW | 3.3 | 0.4% | Jun 9, 2026 | Protection mechanism failure in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature loca... |
| CVE-2026-42770 | LOW | 3.7 | 0.3% | Jun 9, 2026 | Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly check... |
| CVE-2026-42768 | LOW | 3.7 | 0.4% | Jun 9, 2026 | Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacke... |
| CVE-2026-11792 | LOW | 3.3 | 0.3% | Jun 9, 2026 | A heap buffer overflow flaw was found in 389 Directory Server. When audit logging is enabled, the create_masked_entry_st... |
| CVE-2026-11764 | LOW | 3.6 | 0.2% | Jun 9, 2026 | When creating an export of all reusable media, the secrets of connected gift cards were included in the export even if ... |
| CVE-2026-49738 | LOW | 2.1 | 0.4% | Jun 9, 2026 | The path allowance check in GeneralUtility::isAllowedAbsPath() performed a plain string prefix comparison without requir... |
| CVE-2026-41986 | LOW | 2.4 | 0.1% | Jun 9, 2026 | Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availabi... |
| CVE-2026-41974 | LOW | 3.6 | 0.1% | Jun 9, 2026 | Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may aff... |
| CVE-2026-8981 | LOW | 3.5 | 0.1% | Jun 9, 2026 | The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability acros... |
| CVE-2026-44743 | LOW | 3.7 | 0.2% | Jun 9, 2026 | Under certain conditions, when an unauthorized attacker accesses a specific endpoint, SAP Business Objects application l... |
| CVE-2026-11691 | LOW | 3.1 | 0.2% | Jun 9, 2026 | Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote att... |
| CVE-2026-11686 | LOW | 3.1 | 0.2% | Jun 9, 2026 | Insufficient validation of untrusted input in Dawn in Google Chrome on macOS prior to 149.0.7827.103 allowed a remote at... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now