2026 CVE Vulnerabilities
45,191 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12804 | MEDIUM | 4.3 | 0.3% | Jun 21, 2026 | A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-p... |
| CVE-2026-56412 | MEDIUM | 5.9 | 0.1% | Jun 21, 2026 | libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking ... |
| CVE-2026-56411 | MEDIUM | 6.9 | 0.1% | Jun 21, 2026 | xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations. |
| CVE-2026-56410 | MEDIUM | 6.9 | 0.1% | Jun 21, 2026 | xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId. |
| CVE-2026-56409 | MEDIUM | 6.5 | 0.1% | Jun 21, 2026 | xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used. |
| CVE-2026-56408 | MEDIUM | 6.9 | 0.1% | Jun 21, 2026 | libexpat before 2.8.2 has an integer overflow in copyString. |
| CVE-2026-56407 | MEDIUM | 6.9 | 0.1% | Jun 21, 2026 | libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen. |
| CVE-2026-56406 | MEDIUM | 6.9 | 0.1% | Jun 21, 2026 | libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse... |
| CVE-2026-56405 | MEDIUM | 6.9 | 0.1% | Jun 21, 2026 | libexpat before 2.8.2 has an integer overflow in getAttributeId. |
| CVE-2026-56404 | MEDIUM | 6.9 | 0.1% | Jun 21, 2026 | libexpat before 2.8.2 has an integer overflow in addBinding. |
| CVE-2026-56403 | MEDIUM | 6.9 | 0.1% | Jun 21, 2026 | libexpat before 2.8.2 has an integer overflow in storeAtts. |
| CVE-2026-56393 | MEDIUM | 4.8 | 0.2% | Jun 21, 2026 | Craft CMS 4.x (>= 4.0.0-RC1, < 4.17.0-beta.1) and 5.x (>= 5.0.0-RC1, < 5.9.0-beta.1) contain multiple stored cross-site ... |
| CVE-2026-56385 | MEDIUM | 5.3 | 0.2% | Jun 21, 2026 | Craft CMS versions >= 5.0.0-RC1, <= 5.9.13 and >= 4.0.0-RC1, <= 4.17.7 contain an authorization bypass in the assets/pre... |
| CVE-2026-56384 | MEDIUM | 5.3 | 0.2% | Jun 21, 2026 | Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Control Panel user with... |
| CVE-2026-56383 | MEDIUM | 4.8 | 0.2% | Jun 21, 2026 | Craft CMS contains a stored cross-site scripting (XSS) vulnerability in the editableTable.twig component when using the ... |
| CVE-2026-56381 | MEDIUM | 4.8 | 0.1% | Jun 21, 2026 | Craft CMS from version 5.0.0-RC1 contains a stored cross-site scripting vulnerability in the User Permissions page where... |
| CVE-2026-56316 | MEDIUM | 6.9 | 0.2% | Jun 21, 2026 | Cap-go before 12.128.2 contains an information disclosure vulnerability in the OPTIONS /build/upload/:jobId/* endpoint t... |
| CVE-2026-56299 | MEDIUM | 6.9 | 0.4% | Jun 21, 2026 | Capgo before 12.128.2 contains an authentication bypass vulnerability in the /build/upload/:jobId/* endpoint that allows... |
| CVE-2026-56236 | MEDIUM | 6.8 | 0.1% | Jun 21, 2026 | Capgo CLI before 12.128.2 contains arbitrary file overwrite vulnerabilities in login and build credentials operations th... |
| CVE-2026-12799 | MEDIUM | 4.3 | 0.3% | Jun 21, 2026 | A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this issue is the function ui_vi... |
| CVE-2026-12798 | MEDIUM | 6.3 | 0.3% | Jun 21, 2026 | A weakness has been identified in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function load_open... |
| CVE-2026-12797 | MEDIUM | 6.3 | 0.2% | Jun 21, 2026 | A security flaw has been discovered in BerriAI litellm up to 1.82.5. Affected is the function async_pre_call_hook of the... |
| CVE-2026-12796 | MEDIUM | 6.3 | 0.4% | Jun 21, 2026 | A vulnerability was identified in BerriAI litellm up to 1.82.2. This impacts the function get_redirect_response_from_ope... |
| CVE-2026-12789 | MEDIUM | 4.7 | 0.2% | Jun 21, 2026 | A vulnerability was identified in ILIAS Learning Management System 11.0. This issue affects the function ilTrQuery::exec... |
| CVE-2026-12788 | MEDIUM | 6.3 | 0.2% | Jun 21, 2026 | A vulnerability was determined in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This vulnerabi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now