2026 CVE Vulnerabilities
45,590 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0268 | MEDIUM | 4.4 | 0.1% | Jun 10, 2026 | A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffi... |
| CVE-2026-0267 | MEDIUM | 5.5 | 0.1% | Jun 10, 2026 | An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn... |
| CVE-2026-0266 | MEDIUM | 4.8 | 0.1% | Jun 10, 2026 | A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated admi... |
| CVE-2026-50127 | MEDIUM | 5.9 | 0.3% | Jun 10, 2026 | Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did... |
| CVE-2026-46683 | MEDIUM | 6.9 | 0.2% | Jun 10, 2026 | Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.0... |
| CVE-2026-45106 | MEDIUM | 4.6 | 0.2% | Jun 10, 2026 | Weblate is a web based localization tool. Prior to version 2026.5, Weblate's live search preview renders unit source and... |
| CVE-2026-50639 | MEDIUM | 6.5 | 0.3% | Jun 10, 2026 | Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections. The statsd pr... |
| CVE-2026-11626 | MEDIUM | 5.4 | 0.1% | Jun 10, 2026 | CleanWipe Removal Tool (macOS), prior to 16.0.0.65, may be susceptible to an Local Privilege Escalation vulnerability, w... |
| CVE-2026-10740 | MEDIUM | 6.9 | 0.3% | Jun 10, 2026 | Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote... |
| CVE-2026-50569 | MEDIUM | 4.3 | 0.2% | Jun 10, 2026 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic... |
| CVE-2026-50565 | MEDIUM | 4.9 | 0.3% | Jun 10, 2026 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic... |
| CVE-2026-46642 | MEDIUM | 6.1 | 0.2% | Jun 10, 2026 | draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.12, a crafted .drawio file ca... |
| CVE-2026-46618 | MEDIUM | 6.9 | 0.4% | Jun 10, 2026 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic... |
| CVE-2026-20260 | MEDIUM | 4.3 | 0.2% | Jun 10, 2026 | In Splunk SOAR (Security Orchestration, Automation, and Response) versions below 8.5.0, an unauthenticated attacker coul... |
| CVE-2026-20259 | MEDIUM | 5.5 | 0.2% | Jun 10, 2026 | In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.0, 10.3.2512.1... |
| CVE-2026-20258 | MEDIUM | 5.4 | 0.2% | Jun 10, 2026 | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25... |
| CVE-2026-20257 | MEDIUM | 5.7 | 0.2% | Jun 10, 2026 | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25... |
| CVE-2026-20256 | MEDIUM | 5.7 | 0.3% | Jun 10, 2026 | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25... |
| CVE-2026-20255 | MEDIUM | 5.7 | 0.2% | Jun 10, 2026 | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25... |
| CVE-2026-20254 | MEDIUM | 5.7 | 0.2% | Jun 10, 2026 | In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.25... |
| CVE-2026-11596 | MEDIUM | 4.7 | 0.2% | Jun 10, 2026 | In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an au... |
| CVE-2026-46616 | MEDIUM | 6.1 | 0.2% | Jun 10, 2026 | Umbraco is an ASP.NET CMS. Prior to versions 13.14.0 and 17.4.0, some of the Surface Controllers in the CMS provide to s... |
| CVE-2026-46609 | MEDIUM | 4.6 | 0.1% | Jun 10, 2026 | Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4.0, authenticated users are able to inject HTML int... |
| CVE-2026-53698 | MEDIUM | 6.5 | 0.3% | Jun 10, 2026 | Silverpeas through 6.4.6 mishandles the "Personal space" feature that is selected when no componentId is set. |
| CVE-2026-53693 | MEDIUM | 6.9 | 0.3% | Jun 10, 2026 | A stored cross-site scripting vulnerability existed in MISP BSimVis tag rendering code. Several client-side rendering pa... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now