2026 CVE Vulnerabilities
45,307 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54386 | MEDIUM | 6.1 | 0.2% | Jun 17, 2026 | marimo before 0.23.9 contains a reflected cross-site scripting vulnerability in the notebook page that allows unauthenti... |
| CVE-2026-48991 | MEDIUM | 5.5 | 0.1% | Jun 17, 2026 | XianYuLauncher is a Minecraft Java Edition launcher. In versions prior to 1.5.5, sensitive authentication artifacts coul... |
| CVE-2026-48990 | MEDIUM | 5.3 | 0.2% | Jun 17, 2026 | joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar... |
| CVE-2026-48820 | MEDIUM | 6.3 | 0.3% | Jun 17, 2026 | CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1... |
| CVE-2026-48988 | MEDIUM | 5.3 | 0.3% | Jun 17, 2026 | markdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: ... |
| CVE-2026-48821 | MEDIUM | 5.8 | 0.1% | Jun 17, 2026 | Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a DOM-based Cross-Site Scripting (XSS) vuln... |
| CVE-2026-48823 | MEDIUM | 4.8 | 0.1% | Jun 17, 2026 | Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnera... |
| CVE-2026-48822 | MEDIUM | 5.8 | 0.1% | Jun 17, 2026 | Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnera... |
| CVE-2026-48817 | MEDIUM | 5.3 | 0.2% | Jun 17, 2026 | Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint... |
| CVE-2026-10741 | MEDIUM | 4.9 | 0.3% | Jun 17, 2026 | Sonatype Nexus Repository Manager before 3.93.0 contains an authorization vulnerability in the proxy repository configur... |
| CVE-2026-53870 | MEDIUM | 6.8 | 0.1% | Jun 17, 2026 | Hermes Agent before 0.16.0 creates response_store.db and webhook_subscriptions.json with world-readable permissions (mod... |
| CVE-2026-9679 | MEDIUM | 5.9 | 0.3% | Jun 17, 2026 | Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences... |
| CVE-2026-9678 | MEDIUM | 5.9 | 0.3% | Jun 17, 2026 | Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control he... |
| CVE-2026-7300 | MEDIUM | 6.5 | 0.3% | Jun 17, 2026 | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in RTI Connext Professional (Web In... |
| CVE-2026-48591 | MEDIUM | 4.8 | 0.1% | Jun 17, 2026 | Improper Neutralization of Script in Attributes in a Web Page vulnerability in pragdave earmark allows stored cross-site... |
| CVE-2026-2675 | MEDIUM | 6.5 | 0.3% | Jun 17, 2026 | Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Fake th... |
| CVE-2026-20265 | MEDIUM | 4.3 | 0.2% | Jun 17, 2026 | In Splunk AI Toolkit versions below 5.7.4, a low-privileged user that does not hold the "admin" or "power" Splunk roles ... |
| CVE-2026-20178 | MEDIUM | 4.3 | 0.2% | Jun 17, 2026 | A vulnerability in the browser-based version of Cisco Webex App could have allowed an unauthenticated, remote attacker t... |
| CVE-2026-35068 | MEDIUM | 5.7 | 0.2% | Jun 17, 2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in a... |
| CVE-2026-20246 | MEDIUM | 6 | 0.1% | Jun 17, 2026 | A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to e... |
| CVE-2026-20220 | MEDIUM | 6.3 | 0.3% | Jun 17, 2026 | A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenti... |
| CVE-2026-1288 | MEDIUM | 5.5 | 0.1% | Jun 17, 2026 | A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL... |
| CVE-2026-12515 | MEDIUM | 4.3 | 0.2% | Jun 17, 2026 | A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization chec... |
| CVE-2026-55748 | MEDIUM | 6 | 0.2% | Jun 17, 2026 | OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name ... |
| CVE-2026-48142 | MEDIUM | 6.3 | 0.7% | Jun 17, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or p... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now