2026 CVE Vulnerabilities
45,453 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47244 | MEDIUM | 5.3 | 0.3% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina... |
| CVE-2026-47141 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM exposes some process-wide observability bu... |
| CVE-2026-45673 | MEDIUM | 6.8 | 0.3% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina... |
| CVE-2026-45536 | MEDIUM | 4 | 0.1% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina... |
| CVE-2026-44205 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to version 15.106.0, a stored XSS vulnerability in the user prof... |
| CVE-2026-41581 | MEDIUM | 6.9 | 0.2% | Jun 12, 2026 | Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, there is a possible SQL Inject... |
| CVE-2026-28975 | MEDIUM | 6.9 | — | Jun 12, 2026 | ### Impact When `NIOHTTPRequestDecompressor` is configured with `.ratio(N)`, the decompression limit is enforced using ... |
| CVE-2026-28970 | MEDIUM | 6.3 | — | Jun 12, 2026 | Programs using swift-nio is vulnerable to HTTP request smuggling and HTTP response splitting attacks, caused by insuffic... |
| CVE-2026-49993 | MEDIUM | 5.7 | 0.3% | Jun 12, 2026 | Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder from vers... |
| CVE-2026-47200 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.11.0 to before 3.21.6 and 4.0.0-alpha.1 ... |
| CVE-2026-46342 | MEDIUM | 5.4 | 0.1% | Jun 12, 2026 | Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.1.0 to before 3.21.6 and 4.0.0-alpha.1 t... |
| CVE-2026-45670 | MEDIUM | 5.4 | 0.2% | Jun 12, 2026 | Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder versions ... |
| CVE-2026-45669 | MEDIUM | 5.4 | 0.2% | Jun 12, 2026 | Nuxt is an open-source web development framework for Vue.js. From versions 3.4.3 to before 3.21.6 and 4.0.0-alpha.1 to b... |
| CVE-2026-1836 | MEDIUM | 5.3 | 0.1% | Jun 12, 2026 | The system stores the username and password from the login form after submitting the request. This could allow an attack... |
| CVE-2026-49347 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | Quest Bot is an opensource Discord Bot. Prior to version 1.1.8, any user who can access the ticket panel can repeatedly ... |
| CVE-2026-50634 | MEDIUM | 6.5 | 0.3% | Jun 12, 2026 | A vulnerability in Apache CXF's JwsJsonContainerRequestFilter can be exploited to cause CXF to process metadata that was... |
| CVE-2026-50630 | MEDIUM | 6.5 | 0.4% | Jun 12, 2026 | A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate res... |
| CVE-2026-50629 | MEDIUM | 5.3 | 0.5% | Jun 12, 2026 | The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages wi... |
| CVE-2026-50623 | MEDIUM | 4.8 | 0.4% | Jun 12, 2026 | An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 't... |
| CVE-2026-48914 | MEDIUM | 6.7 | 0.1% | Jun 12, 2026 | A flaw was found in QEMU's virtio-blk device. The issue arises because the device does not properly validate the size of... |
| CVE-2026-11847 | MEDIUM | 5.3 | 0.3% | Jun 12, 2026 | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Path Traversal vulnerability, allowi... |
| CVE-2026-11844 | MEDIUM | 6.9 | 0.4% | Jun 12, 2026 | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a Arbitrary File Read vulnerability, all... |
| CVE-2026-12058 | MEDIUM | 5.3 | 0.2% | Jun 12, 2026 | The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed. |
| CVE-2026-9271 | MEDIUM | 5.9 | 0.1% | Jun 12, 2026 | Vulnerability Title |
| CVE-2026-12060 | MEDIUM | 6.9 | 0.3% | Jun 12, 2026 | Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticate... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now