2026 CVE Vulnerabilities
45,376 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-24610 | MEDIUM | 4.3 | 0.2% | Jun 17, 2026 | Subscriber Broken Access Control in MetForm Pro <= 3.9.1 versions. |
| CVE-2026-24575 | MEDIUM | 4.3 | 0.3% | Jun 17, 2026 | Subscriber Broken Access Control in WishList Member X <= 3.29.0 versions. |
| CVE-2026-12491 | MEDIUM | 4.8 | 0.2% | Jun 17, 2026 | A flaw was found in vLLM, an open-source library for large language model inference. This vulnerability arises from impr... |
| CVE-2026-12469 | MEDIUM | 4.3 | 0.2% | Jun 17, 2026 | Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to leak cross-ori... |
| CVE-2026-12463 | MEDIUM | 4.7 | 0.1% | Jun 17, 2026 | Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker who ha... |
| CVE-2026-12461 | MEDIUM | 6.5 | 0.2% | Jun 17, 2026 | Out of bounds read in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to obtain pot... |
| CVE-2026-12460 | MEDIUM | 4.2 | 0.2% | Jun 17, 2026 | Insufficient policy enforcement in File System Access in Google Chrome prior to 149.0.7827.155 allowed a remote attacker... |
| CVE-2026-12459 | MEDIUM | 6.1 | 0.2% | Jun 17, 2026 | Inappropriate implementation in Serial in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to inject arbi... |
| CVE-2026-12457 | MEDIUM | 4.2 | 0.1% | Jun 17, 2026 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had co... |
| CVE-2026-12456 | MEDIUM | 4.2 | 0.1% | Jun 17, 2026 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a ... |
| CVE-2026-12453 | MEDIUM | 4.2 | 0.2% | Jun 17, 2026 | Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.155 allowed a remote attacker w... |
| CVE-2026-12450 | MEDIUM | 6.5 | 0.2% | Jun 17, 2026 | Inappropriate implementation in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to obtain poten... |
| CVE-2026-12446 | MEDIUM | 4.3 | 0.2% | Jun 17, 2026 | Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to leak cro... |
| CVE-2026-12444 | MEDIUM | 5.5 | 0.1% | Jun 17, 2026 | Out of bounds read in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to obtain ... |
| CVE-2026-12115 | MEDIUM | 6.6 | 0.5% | Jun 17, 2026 | The Counter Box – Add Countdowns, Timers & Dynamic Counters to WordPress plugin for WordPress is vulnerable to PHP Objec... |
| CVE-2026-11975 | MEDIUM | 6.2 | 0.3% | Jun 17, 2026 | Stored cross-site scripting (XSS) in NewsItemApiController In SimplCommerce prior to commit 6142d3b5 allows an authentic... |
| CVE-2026-10839 | MEDIUM | 5.1 | 0.4% | Jun 17, 2026 | Open redirection vulnerability in the authentication system allows an attacker to use manipulated values in the X-Forwar... |
| CVE-2026-10837 | MEDIUM | 5.1 | 0.3% | Jun 17, 2026 | Open redirection vulnerability due to insufficient validation of the X-Forwarded-Host HTTP header. An attacker could cre... |
| CVE-2026-10836 | MEDIUM | 5.1 | 0.3% | Jun 17, 2026 | Improper handling of HTTP headers that allows a remote attacker to manipulate the value of the Host header using special... |
| CVE-2026-0064 | MEDIUM | 5.5 | 0.1% | Jun 17, 2026 | In multiple places, there is a possible persistent denial of service due to resource exhaustion. This could lead to loca... |
| CVE-2026-46979 | MEDIUM | 6.5 | 0.3% | Jun 17, 2026 | Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Integration and ... |
| CVE-2026-46877 | MEDIUM | 6 | 0.2% | Jun 17, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v... |
| CVE-2026-46871 | MEDIUM | 6.5 | 0.3% | Jun 17, 2026 | Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is... |
| CVE-2026-46869 | MEDIUM | 6.5 | 0.2% | Jun 17, 2026 | Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Dump and Load). Supported versions that are... |
| CVE-2026-46825 | MEDIUM | 6 | 0.2% | Jun 17, 2026 | Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: VMSVGA device). The supported v... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now