2026 CVE Vulnerabilities
45,094 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-52814 | MEDIUM | 5.5 | 0.5% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs built-in Go SSH server is vulnerable to an una... |
| CVE-2026-52809 | MEDIUM | 6.8 | 0.2% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, password-reset tokens are generated using conf.Auth.Act... |
| CVE-2026-52807 | MEDIUM | 4.8 | 0.5% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, in new_form.tmpl, milestone names are rendered with Go'... |
| CVE-2026-52804 | MEDIUM | 5.5 | 0.5% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, a repository admin collaborator can escalate their priv... |
| CVE-2026-52802 | MEDIUM | 5.4 | 0.6% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, an open redirect vulnerability exists in Gogs where att... |
| CVE-2026-52795 | MEDIUM | 4.3 | 0.2% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. In 0.14.3 and earlier, any authenticated user can watch a private reposi... |
| CVE-2026-50128 | MEDIUM | 5.3 | 0.1% | Jun 24, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. From 4.3.0 until 4.5.11 and 4.4.18, Mastodon... |
| CVE-2026-49278 | MEDIUM | 6.7 | 0.2% | Jun 24, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, ... |
| CVE-2026-47733 | MEDIUM | 4.4 | 0.1% | Jun 24, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, the ImageElement comp... |
| CVE-2026-32315 | MEDIUM | 5.5 | 2.9% | Jun 24, 2026 | motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Version... |
| CVE-2026-31978 | MEDIUM | 6.5 | 0.4% | Jun 24, 2026 | motionEye (mEye) is an online interface for motion software, which is a video surveillance program with motion detection... |
| CVE-2026-13208 | MEDIUM | 6.5 | 0.1% | Jun 24, 2026 | A flaw was found in KubeVirt's virt-handler domain notify server. The gRPC handlers for HandleDomainEvent and HandleK8SE... |
| CVE-2026-48028 | MEDIUM | 6.5 | 0.1% | Jun 24, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodo... |
| CVE-2026-46349 | MEDIUM | 5.3 | 0.2% | Jun 24, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodo... |
| CVE-2026-53949 | MEDIUM | 5.3 | 0.2% | Jun 24, 2026 | Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public ... |
| CVE-2026-53948 | MEDIUM | 5.4 | 0.1% | Jun 24, 2026 | Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied C... |
| CVE-2026-53947 | MEDIUM | 5.3 | 0.2% | Jun 24, 2026 | Ghost is a Node.js content management system. From 5.18.0 until 6.21.1, a discrepancy in responses from the members sign... |
| CVE-2026-53946 | MEDIUM | 5.4 | 0.1% | Jun 24, 2026 | Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, when re-rendering posts, Ghost would refetch mis... |
| CVE-2026-53945 | MEDIUM | 4 | 0.1% | Jun 24, 2026 | Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghost’s private-IP check for outbound HTTP reques... |
| CVE-2026-53944 | MEDIUM | 5.8 | 0.2% | Jun 24, 2026 | Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, when making an external request, it is possible t... |
| CVE-2026-49220 | MEDIUM | 5.7 | 0.2% | Jun 24, 2026 | Jellyfin is an open source self hosted media server. Prior to 10.11.9, a potential XSS attack exists in Jellyfin which c... |
| CVE-2026-13034 | MEDIUM | 4.7 | 0.1% | Jun 24, 2026 | Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had com... |
| CVE-2026-13030 | MEDIUM | 5.3 | 0.2% | Jun 24, 2026 | Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to obtain potenti... |
| CVE-2026-13024 | MEDIUM | 4.2 | 0.1% | Jun 24, 2026 | Insufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.197 allowed a remote attac... |
| CVE-2026-13023 | MEDIUM | 5.3 | 0.2% | Jun 24, 2026 | Uninitialized Use in GPU in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the rend... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now