2026 CVE Vulnerabilities
45,207 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56235 | MEDIUM | 6.9 | 0.3% | Jun 20, 2026 | Cap-go capgo before 12.128.2 contains an authorization bypass in several Supabase PostgREST RPC functions (get_app_metri... |
| CVE-2026-56228 | MEDIUM | 6.9 | 0.3% | Jun 20, 2026 | Capgo before 12.128.2 fails to enforce a maximum value on the minimum password length field in its password policy confi... |
| CVE-2026-56227 | MEDIUM | 5.4 | 0.2% | Jun 20, 2026 | Capgo before 12.128.2 contains a server-side request forgery vulnerability in webhook URL validation that allows loopbac... |
| CVE-2026-56218 | MEDIUM | 6.9 | 0.2% | Jun 20, 2026 | Capgo before 12.128.2 fails to strip EXIF metadata including GPS geolocation data from uploaded images, allowing informa... |
| CVE-2026-12673 | MEDIUM | 5.9 | 0.3% | Jun 20, 2026 | Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privilege escalati... |
| CVE-2026-12119 | MEDIUM | 6.5 | 0.3% | Jun 20, 2026 | The Simple File List plugin for WordPress is vulnerable to unauthorized file operations due to a missing authorization c... |
| CVE-2026-56213 | MEDIUM | 6.9 | 0.2% | Jun 20, 2026 | Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.upsert_version_meta SECURITY DEFINER ... |
| CVE-2026-56212 | MEDIUM | 5.1 | 0.2% | Jun 20, 2026 | Capgo before 12.128.2 contains an authentication logic flaw: a user with permission to manage team or organization secur... |
| CVE-2026-56080 | MEDIUM | 6.9 | 0.3% | Jun 19, 2026 | Capgo before 12.128.2 contains a flaw in the Enforce Password Policy feature: after a Super Admin enables the policy and... |
| CVE-2026-49337 | MEDIUM | 4.3 | 0.2% | Jun 19, 2026 | libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265... |
| CVE-2026-48129 | MEDIUM | 6.5 | 0.3% | Jun 19, 2026 | Kestra is an open-source, event-driven orchestration platform. Prior to versions 1.3.19, 1.2.19, 1.1.19, and 1.0.43, Kes... |
| CVE-2026-32208 | MEDIUM | 5.4 | 0.3% | Jun 19, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Entra ID allows an aut... |
| CVE-2026-49345 | MEDIUM | 5.3 | 0.5% | Jun 19, 2026 | Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, ... |
| CVE-2026-49342 | MEDIUM | 5.3 | 0.3% | Jun 19, 2026 | YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache ... |
| CVE-2026-49336 | MEDIUM | 5.5 | 0.7% | Jun 19, 2026 | @microsoft/kiota-http-fetchlibrary provides TypeScript libraries for Kiota-generated API clients. In versions 1.0.0-prev... |
| CVE-2026-49288 | MEDIUM | 4.3 | 0.2% | Jun 19, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, an authenticated Con... |
| CVE-2026-27878 | MEDIUM | 6.5 | 0.2% | Jun 19, 2026 | A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive... |
| CVE-2026-12726 | MEDIUM | 6.3 | 0.2% | Jun 19, 2026 | A flaw was found in the AWX GitHub webhook integration. When processing GitHub pull_request webhooks, the controller sto... |
| CVE-2026-12238 | MEDIUM | 5.3 | 0.2% | Jun 19, 2026 | The WP Go Maps – Most Popular Map Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up t... |
| CVE-2026-49359 | MEDIUM | 6.5 | 0.2% | Jun 19, 2026 | PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/... |
| CVE-2026-49271 | MEDIUM | 6.5 | 0.2% | Jun 19, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to version 1.22.1, the uncompressed HEIF decoder valid... |
| CVE-2026-3196 | MEDIUM | 5.5 | 0.1% | Jun 19, 2026 | An integer overflow vulnerability was found in the virtio-snd device via PCM_INFO requests from the guest. A malicious g... |
| CVE-2026-12622 | MEDIUM | 5.4 | 0.2% | Jun 19, 2026 | The GridTime 3000 GNSS Time Server has an open redirect vulnerability in the password change form submission. This issu... |
| CVE-2026-12621 | MEDIUM | 5.4 | 0.2% | Jun 19, 2026 | Improper neutralization of input during web page generation XSS vulnerability in the GridTime 3000 (password reset form... |
| CVE-2026-12620 | MEDIUM | 6.5 | 0.2% | Jun 19, 2026 | The GridTime 3000 GNSS Time Server leaks the access token in the URL parameters of some endpoints. This issue affects G... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now