2026 CVE Vulnerabilities
45,261 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9692 | MEDIUM | 5.3 | 0.3% | Jun 18, 2026 | Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The default session id ... |
| CVE-2026-55392 | MEDIUM | 6.7 | 0.1% | Jun 18, 2026 | NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size ... |
| CVE-2026-48937 | MEDIUM | 5.3 | 0.4% | Jun 18, 2026 | A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This v... |
| CVE-2026-47833 | MEDIUM | 6.9 | 0.1% | Jun 18, 2026 | setupBpmLogs follows symlink for bpm.log open and chown — container-to-host privilege escalation via /etc/shadow. A comp... |
| CVE-2026-48986 | MEDIUM | 4.7 | 0.1% | Jun 18, 2026 | pam_usb provides hardware authentication for Linux using removable media. In pam_usb 0.9.1 and earlier, usb_get_process_... |
| CVE-2026-48985 | MEDIUM | 5.5 | 0.1% | Jun 18, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. In versions 0.9.1 and below, pusb_is_... |
| CVE-2026-48984 | MEDIUM | 4.7 | 0.1% | Jun 18, 2026 | pam_usb provides hardware authentication for Linux using ordinary removable media. In versions 0.9.1 and below, the xfre... |
| CVE-2026-56024 | MEDIUM | 6.5 | 0.1% | Jun 18, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Saad Iqbal WP EasyPay allows Cross Site Request Forgery. This issue ... |
| CVE-2026-56022 | MEDIUM | 6.9 | 0.5% | Jun 18, 2026 | Webmin accepts basic authentication without session cookies when an attacker provides the 'User-Agent: webmin' header, a... |
| CVE-2026-56021 | MEDIUM | 6.9 | 0.5% | Jun 18, 2026 | Webmin allows unauthenticated attackers to read the contents of any file ending in .conf within module directories, due ... |
| CVE-2026-55205 | MEDIUM | 6.9 | 0.3% | Jun 18, 2026 | Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oa... |
| CVE-2026-54106 | MEDIUM | 5.1 | 0.3% | Jun 18, 2026 | The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac... |
| CVE-2026-54105 | MEDIUM | 6.9 | 0.3% | Jun 18, 2026 | The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac... |
| CVE-2026-11982 | MEDIUM | 5.1 | 0.3% | Jun 18, 2026 | Grav 2.0.0-rc.9 with Admin2 2.0.0-rc.14 contains a stored cross-site scripting (XSS) vulnerability in the Admin2 Pages A... |
| CVE-2026-22551 | MEDIUM | 6.5 | 0.2% | Jun 18, 2026 | In Eclipse Theia versions prior to 1.71.0, the AI chat rendered Markdown image tags from AI responses, triggering HTTP r... |
| CVE-2026-11791 | MEDIUM | 5 | 0.3% | Jun 18, 2026 | A flaw was found in 389 Directory Server. During schema reload, the attr_syntax_swap_ht() function unconditionally frees... |
| CVE-2026-56009 | MEDIUM | 5.9 | 0.1% | Jun 18, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricksable for Bri... |
| CVE-2026-56007 | MEDIUM | 5.9 | 0.1% | Jun 18, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in OceanWP Ocean Prod... |
| CVE-2026-54221 | MEDIUM | 5.1 | 0.3% | Jun 18, 2026 | UBB.threads is vulnerable to Reflected XSS. The application improperly handles user input in certain requests, enabling ... |
| CVE-2026-54219 | MEDIUM | 5.1 | 0.3% | Jun 18, 2026 | UBB.threads is vulnerable to Stored XSS via user posts and user profile fields. The application fails to properly saniti... |
| CVE-2026-44942 | MEDIUM | 6.5 | 0.3% | Jun 18, 2026 | A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series... |
| CVE-2026-42490 | MEDIUM | 6.5 | 0.2% | Jun 18, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-42489 | MEDIUM | 5.3 | 0.1% | Jun 18, 2026 | [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to whi... |
| CVE-2026-12539 | MEDIUM | 5.7 | 0.1% | Jun 18, 2026 | Docker Sandboxes (sbx) blocks ICMP egress with an authorizer applied only at network-creation time, and does not re-appl... |
| CVE-2026-12527 | MEDIUM | 6 | 0.2% | Jun 18, 2026 | A broken authorization boundary in the RTSP media delivery pipeline of Shenzhen Liandian Communication Technology LTD V3... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now