2026 CVE Vulnerabilities
45,449 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-52721 | MEDIUM | 5.3 | 0.1% | Jun 15, 2026 | Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trig... |
| CVE-2026-52718 | MEDIUM | 6.5 | 0.3% | Jun 15, 2026 | A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse... |
| CVE-2026-50892 | MEDIUM | 6.5 | 0.2% | Jun 15, 2026 | Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows auth... |
| CVE-2026-50876 | MEDIUM | 5.4 | 0.2% | Jun 15, 2026 | A cross-site scripting (XSS) vulnerability in Deck9 Input v2.0.1 allows attackers to execute arbitrary web scripts or HT... |
| CVE-2026-49953 | MEDIUM | 6.9 | 0.4% | Jun 15, 2026 | Discuz! X5.0 releases 20260320 through 20260610 contains a CAPTCHA bypass vulnerability that allows unauthenticated remo... |
| CVE-2026-39197 | MEDIUM | 6.5 | 0.3% | Jun 15, 2026 | An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Serv... |
| CVE-2026-37216 | MEDIUM | 6.1 | 0.2% | Jun 15, 2026 | Ruoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /system/notice/add. |
| CVE-2026-36933 | MEDIUM | 6.8 | 0.2% | Jun 15, 2026 | An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker to execute arbitrary code vi... |
| CVE-2026-36521 | MEDIUM | 6.1 | 0.2% | Jun 15, 2026 | PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in the site configuration management module. |
| CVE-2026-11931 | MEDIUM | 6.8 | 0.1% | Jun 15, 2026 | Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication tok... |
| CVE-2026-8358 | MEDIUM | 5.4 | 0.2% | Jun 15, 2026 | LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document ... |
| CVE-2026-8356 | MEDIUM | 5.4 | 0.1% | Jun 15, 2026 | LibreOffice can import presentations in the legacy binary PPT format. A stack buffer overflow existed when importing a c... |
| CVE-2026-6047 | MEDIUM | 5.4 | 0.1% | Jun 15, 2026 | LibreOffice can import documents in the OOXML format (DOCX). A heap buffer overflow existed when replaying deferred pars... |
| CVE-2026-6045 | MEDIUM | 5.4 | 0.1% | Jun 15, 2026 | LibreOffice can import EMF+ graphics, which may be embedded in documents. A heap buffer overflow existed when importing ... |
| CVE-2026-6039 | MEDIUM | 5.4 | 0.2% | Jun 15, 2026 | LibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow existed when importing a ... |
| CVE-2026-49294 | MEDIUM | 6.1 | 0.1% | Jun 15, 2026 | Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. Versions 3.6.3 and... |
| CVE-2026-20262 | MEDIUM | 6.5 | 28.2% | Jun 15, 2026 | A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, r... |
| CVE-2026-9595 | MEDIUM | 4.3 | 0.2% | Jun 15, 2026 | Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts... |
| CVE-2026-8683 | MEDIUM | 6.5 | 0.2% | Jun 15, 2026 | Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Matterm... |
| CVE-2026-10634 | MEDIUM | 5.3 | 0.3% | Jun 15, 2026 | Zephyr's native TCP stack iterates the global connection list in net_tcp_foreach() (subsys/net/ip/tcp.c) using the SYS_S... |
| CVE-2026-48969 | MEDIUM | 6.5 | 0.2% | Jun 15, 2026 | Subscriber Broken Access Control in Really Simple SSL <= 9.5.9 versions. |
| CVE-2026-34030 | MEDIUM | 6.9 | 0.3% | Jun 15, 2026 | The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, does not sufficiently validate the branch code wh... |
| CVE-2026-34029 | MEDIUM | 6.8 | 0.1% | Jun 15, 2026 | The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a hard-coded cryptographic key in the Sa... |
| CVE-2026-34028 | MEDIUM | 6.9 | 0.4% | Jun 15, 2026 | The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, exposes web-accessible file paths that are not pr... |
| CVE-2026-34027 | MEDIUM | 5.3 | 0.3% | Jun 15, 2026 | The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains insufficient server-side file type valid... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now