2026 CVE Vulnerabilities
45,152 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8059 | MEDIUM | 6.1 | 0.1% | Jun 22, 2026 | IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 is vulnerable to cross-site script... |
| CVE-2026-7253 | MEDIUM | 6 | 0.2% | Jun 22, 2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway are vulnerable to SQL injection. A privileged user could send ... |
| CVE-2026-54267 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-54266 | MEDIUM | 6.1 | 0.1% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-54265 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-54264 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-53655 | MEDIUM | 5.5 | 0.1% | Jun 22, 2026 | node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= recor... |
| CVE-2026-53550 | MEDIUM | 5.3 | 0.3% | Jun 22, 2026 | js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithm... |
| CVE-2026-52725 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-50557 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-41047 | MEDIUM | 5.5 | 0.1% | Jun 22, 2026 | Lack of authentication when using the "snapshot diff" functions in qSnapper before version 1.3.3 allowed a local attacke... |
| CVE-2026-12725 | MEDIUM | 5.9 | 0.4% | Jun 22, 2026 | A heap-based buffer overflow was found in dnsmasq. When DNSSEC validation and query logging are both enabled, logging of... |
| CVE-2026-12549 | MEDIUM | 4.8 | 0.3% | Jun 22, 2026 | The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a gene... |
| CVE-2026-12479 | MEDIUM | 6.1 | 0.3% | Jun 22, 2026 | A path traversal vulnerability exists in keras-team/keras version 3.14.0, specifically in the `DiskIOStore.make` method ... |
| CVE-2026-11943 | MEDIUM | 4.8 | 0.3% | Jun 22, 2026 | Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the document timeline shown on i... |
| CVE-2026-11942 | MEDIUM | 4.8 | 0.3% | Jun 22, 2026 | Akaunting 3.1.21 contains an authenticated stored cross-site scripting vulnerability in the reusable delete confirmation... |
| CVE-2026-11372 | MEDIUM | 5.4 | 0.2% | Jun 22, 2026 | IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an... |
| CVE-2026-9162 | MEDIUM | 4.3 | 0.2% | Jun 22, 2026 | Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to invalidate cached ... |
| CVE-2026-9029 | MEDIUM | 5.4 | 0.3% | Jun 22, 2026 | A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer ... |
| CVE-2026-7167 | MEDIUM | 6.9 | 0.4% | Jun 22, 2026 | The vulnerability arises when the system fails to properly validate the 'email' field during the authentication process,... |
| CVE-2026-6673 | MEDIUM | 6.4 | 0.2% | Jun 22, 2026 | Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to authenticate Atlas... |
| CVE-2026-6062 | MEDIUM | 6.4 | 0.2% | Jun 22, 2026 | Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 Fail to validate channel o... |
| CVE-2026-5139 | MEDIUM | 5.4 | 0.2% | Jun 22, 2026 | Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to enforce administra... |
| CVE-2026-56450 | MEDIUM | 5.1 | 0.3% | Jun 22, 2026 | AIL did not restrict repeated failed attempts to verify a two-factor authentication (OTP) code. An attacker who had reac... |
| CVE-2026-10601 | MEDIUM | 4.3 | 0.3% | Jun 22, 2026 | A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach uni... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now