2026 CVE Vulnerabilities
45,307 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-20220 | MEDIUM | 6.3 | 0.3% | Jun 17, 2026 | A vulnerability in the web-based management interface of Cisco Crosswork Network Controller could allow an authenti... |
| CVE-2026-1288 | MEDIUM | 5.5 | 0.1% | Jun 17, 2026 | A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL... |
| CVE-2026-12515 | MEDIUM | 4.3 | 0.2% | Jun 17, 2026 | A flaw was found in Katello's of Red Hat Satellite. A content upload functionality where insufficient authorization chec... |
| CVE-2026-55748 | MEDIUM | 6 | 0.2% | Jun 17, 2026 | OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name ... |
| CVE-2026-48142 | MEDIUM | 6.3 | 0.7% | Jun 17, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or p... |
| CVE-2026-48117 | MEDIUM | 6.8 | 0.2% | Jun 17, 2026 | DroneAware is a drone detection platform. The centralized DroneAware server backing droneaware.io was vulnerable to an a... |
| CVE-2026-40641 | MEDIUM | 4.8 | 0.1% | Jun 17, 2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Use of a Broken or Risky Cryptographic Algorithm vuln... |
| CVE-2026-35162 | MEDIUM | 6.5 | 0.2% | Jun 17, 2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Access Control vulnerability. A low privileg... |
| CVE-2026-12528 | MEDIUM | 5.4 | 0.2% | Jun 17, 2026 | A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c. A malformed ACI (Acce... |
| CVE-2026-11311 | MEDIUM | 6.5 | 0.6% | Jun 17, 2026 | When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX... |
| CVE-2026-10850 | MEDIUM | 5.4 | 0.2% | Jun 17, 2026 | Plane CE 1.3.1 allows a low-privileged project member to submit arbitrary HTML/JS in the description_html field when cre... |
| CVE-2026-9591 | MEDIUM | 6.9 | 0.2% | Jun 17, 2026 | Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthent... |
| CVE-2026-54817 | MEDIUM | 6.5 | 0.3% | Jun 17, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in FluxBuilder MStore API allows Password Recover... |
| CVE-2026-52716 | MEDIUM | 6.5 | 0.4% | Jun 17, 2026 | Unauthenticated Arbitrary File Deletion in WorkScout-Core <= 1.7.11 versions. |
| CVE-2026-8607 | MEDIUM | 6.4 | 0.3% | Jun 17, 2026 | The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress ... |
| CVE-2026-8494 | MEDIUM | 6.4 | 0.2% | Jun 17, 2026 | The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admi... |
| CVE-2026-8383 | MEDIUM | 5.3 | 0.2% | Jun 17, 2026 | The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint behind the `e... |
| CVE-2026-7850 | MEDIUM | 5.9 | 0.1% | Jun 17, 2026 | The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before injecting t... |
| CVE-2026-54196 | MEDIUM | 6.8 | 0.2% | Jun 17, 2026 | Subscriber Privilege Escalation in JetFormBuilder <= 3.6.1 versions. |
| CVE-2026-49072 | MEDIUM | 6.5 | 0.3% | Jun 17, 2026 | Unauthenticated Broken Access Control in WooCommerce Anti-Fraud <= 7.2.6 versions. |
| CVE-2026-49071 | MEDIUM | 6.5 | 0.3% | Jun 17, 2026 | Unauthenticated Broken Authentication in WooCommerce Dropshipping <= 5.2.4 versions. |
| CVE-2026-48783 | MEDIUM | 4.8 | 0.2% | Jun 17, 2026 | Postiz is an AI social media scheduling tool. Versions prior to 2.21.8 contained an unauthenticated endpoint that accept... |
| CVE-2026-48782 | MEDIUM | 6.8 | 0.3% | Jun 17, 2026 | Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. In versions 1.56.0 t... |
| CVE-2026-47340 | MEDIUM | 6.5 | 0.4% | Jun 17, 2026 | Allow authenticated users to access alert instances associated with alert groups they do not have permission to access. ... |
| CVE-2026-47277 | MEDIUM | 6.5 | 0.4% | Jun 17, 2026 | Runtipi is a personal homeserver orchestrator. In versions 4.9.1 through 4.9.3, Runtipi serves marketplace app logos fro... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now