2026 CVE Vulnerabilities
45,452 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9641 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default alg... |
| CVE-2026-5792 | MEDIUM | 6.5 | 0.2% | Jun 12, 2026 | Authentication bypass by spoofing vulnerability in Hedef Media Promotion Interactive Media Marketing Inc. Related Market... |
| CVE-2026-53568 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, there is a stored XSS vulnerab... |
| CVE-2026-50560 | MEDIUM | 5.3 | 0.3% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina... |
| CVE-2026-50090 | MEDIUM | 6.1 | 0.3% | Jun 12, 2026 | The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due ... |
| CVE-2026-50089 | MEDIUM | 6.1 | 0.1% | Jun 12, 2026 | The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redire... |
| CVE-2026-50088 | MEDIUM | 4.7 | 0.2% | Jun 12, 2026 | The Aqara Developer Portal (developer.aqara.com) and shared test environments (developer-test.aqara.com, aiot-test.aqara... |
| CVE-2026-50087 | MEDIUM | 6.1 | 0.2% | Jun 12, 2026 | The Aqara IAM/SSO gateway (gw-builder.aqara.com) exhibits a cross-origin request sharing vulnerability, which is an inst... |
| CVE-2026-50084 | MEDIUM | 6.5 | 0.2% | Jun 12, 2026 | The Aqara Cloud Production API (open-cn.aqara.com/v3.0/open/api) would authorize any valid developer token for access to... |
| CVE-2026-50082 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | The Aqara Cloud Developer Portal (developer.aqara.com) issued a developer token to any email address supplied by the att... |
| CVE-2026-50026 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, a lack of permission checks in... |
| CVE-2026-50020 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina... |
| CVE-2026-50009 | MEDIUM | 4.8 | 0.2% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final,... |
| CVE-2026-47190 | MEDIUM | 4.4 | 0.3% | Jun 12, 2026 | IPAM is the IP address Manager for Cluster API Provider Metal3. Prior to versions 1.11.7, 1.12.4, and 1.13.0, the IPAM c... |
| CVE-2026-47182 | MEDIUM | 5.3 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to version 16.17.4, any authenticated user can access private fi... |
| CVE-2026-46690 | MEDIUM | 5.8 | 0.1% | Jun 12, 2026 | unbounded_spsc is an "unbounded" extension of bounded_spsc_queue. In versions 0.2.0 and prior, sender::send pointer-as-v... |
| CVE-2026-44976 | MEDIUM | 5.3 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to version 16.17.4, any user can modify any field in any Onboard... |
| CVE-2026-44975 | MEDIUM | 5.3 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can res... |
| CVE-2026-44967 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | OpenTelemetry-cpp is the C++ implementation of OpenTelemetry. Prior to release 1.27.0, the OTLP HTTP exporters (traces/m... |
| CVE-2026-44208 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "su... |
| CVE-2026-44207 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, an IDOR vulnerability allows a... |
| CVE-2026-44206 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, DB Schema Enumeration is possi... |
| CVE-2026-8694 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attack... |
| CVE-2026-53722 | MEDIUM | 5.4 | 0.2% | Jun 12, 2026 | Nuxt is an open-source web development framework for Vue.js. Prior to versions 3.21.7 and 4.4.7, <NuxtLink> did not vali... |
| CVE-2026-47739 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, stored XSS in Note was possibl... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now