2026 CVE Vulnerabilities
45,440 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12301 | MEDIUM | 5.3 | 0.3% | Jun 16, 2026 | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
| CVE-2026-12300 | MEDIUM | 5.3 | 0.3% | Jun 16, 2026 | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152 and Thunderbird 152. |
| CVE-2026-12299 | MEDIUM | 5.4 | 0.3% | Jun 16, 2026 | JIT miscompilation in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, F... |
| CVE-2026-12298 | MEDIUM | 5.4 | 0.3% | Jun 16, 2026 | Memory safety bug fixed in Firefox 152. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Thunderbird 152... |
| CVE-2026-8484 | MEDIUM | 4.8 | 0.1% | Jun 16, 2026 | A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" wrapper due to a lack of size verification for th... |
| CVE-2026-10828 | MEDIUM | 6.9 | 0.3% | Jun 16, 2026 | A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPor... |
| CVE-2026-54197 | MEDIUM | 6.5 | 0.2% | Jun 16, 2026 | Unauthenticated Sensitive Data Exposure in GetGenie <= 4.4.1 versions. |
| CVE-2026-54190 | MEDIUM | 6.5 | 0.2% | Jun 16, 2026 | Unauthenticated Broken Access Control in Envira Photo Gallery <= 1.12.5 versions. |
| CVE-2026-52714 | MEDIUM | 5.9 | 0.2% | Jun 16, 2026 | Unauthenticated Broken Access Control in SEO Plugin by Squirrly SEO <= 12.4.16 versions. |
| CVE-2026-40809 | MEDIUM | 6.5 | 0.2% | Jun 16, 2026 | Missing Authorization vulnerability in Rara Themes Metro Magazine allows Exploiting Incorrectly Configured Access Contro... |
| CVE-2026-2381 | MEDIUM | 6.5 | 0.3% | Jun 16, 2026 | The WooCommerce Stripe Payment Gateway plugin for WordPress is vulnerable to unauthorized modification of data due to a ... |
| CVE-2026-10093 | MEDIUM | 6.4 | 0.2% | Jun 16, 2026 | The File Sharing & Download Manager – User Private Files plugin for WordPress is vulnerable to Stored Cross-Site Scripti... |
| CVE-2026-9187 | MEDIUM | 5.3 | 0.2% | Jun 16, 2026 | The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up t... |
| CVE-2026-5149 | MEDIUM | 6.5 | 0.2% | Jun 16, 2026 | The RTMKit plugin for WordPress is vulnerable to Incorrect Authorization in all versions up to, and including, 2.0.7 Thi... |
| CVE-2026-50255 | MEDIUM | 6.7 | 0.1% | Jun 16, 2026 | Incorrect default permissions issue exists in Optical Disc Archive Software for Windows 5.5.3 and earlier. If this vulne... |
| CVE-2026-10780 | MEDIUM | 4.3 | 0.2% | Jun 16, 2026 | The Static Block plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inclu... |
| CVE-2026-10635 | MEDIUM | 6.3 | 0.2% | Jun 16, 2026 | On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, the page-table code (arch/xtensa/core/ptables.c) maintain... |
| CVE-2026-6964 | MEDIUM | 5.3 | 0.3% | Jun 16, 2026 | The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and i... |
| CVE-2026-42014 | MEDIUM | 6.6 | 0.1% | Jun 16, 2026 | A flaw was found in GnuTLS. The `gnutls_pkcs11_token_set_pin` function, used for changing the Security Officer PIN, can ... |
| CVE-2026-1766 | MEDIUM | 6.1 | 0.2% | Jun 16, 2026 | A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor, specifically within the tracke... |
| CVE-2026-1765 | MEDIUM | 5.6 | 0.1% | Jun 16, 2026 | A flaw was found in the `tracker-extract-mp3` component of GNOME localsearch (previously known as tracker-miners). This ... |
| CVE-2026-1764 | MEDIUM | 5.6 | 0.2% | Jun 16, 2026 | A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially craf... |
| CVE-2026-12162 | MEDIUM | 5.5 | 0.1% | Jun 16, 2026 | Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an ... |
| CVE-2026-48157 | MEDIUM | 6.1 | 0.2% | Jun 15, 2026 | Slim is a PHP micro framework that enables users to write simple web applications and APIs. In versions 4.4.0 through 4.... |
| CVE-2026-49775 | MEDIUM | 6.5 | 0.2% | Jun 15, 2026 | Unauthenticated Broken Access Control in Welcart e-Commerce <= 2.11.28 versions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now