2026 CVE Vulnerabilities
45,788 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48859 | MEDIUM | 5.3 | 0.4% | Jun 10, 2026 | Observable Timing Discrepancy vulnerability in Erlang/OTP ssh (ssh_auth, ssh_options modules) allows unauthenticated rem... |
| CVE-2026-48858 | MEDIUM | 6.5 | 0.2% | Jun 10, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Erlang/OTP ftp (ftp_internal module) allows FTP bounce attacks and S... |
| CVE-2026-48856 | MEDIUM | 6.5 | 0.3% | Jun 10, 2026 | Sensitive Data Exposure vulnerability in Erlang OTP inets (httpc_response module) allows Retrieve Embedded Sensitive Dat... |
| CVE-2026-48855 | MEDIUM | 6.5 | 0.3% | Jun 10, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Erlang OTP ssh (ssh_sftpd module) allows Fil... |
| CVE-2026-48096 | MEDIUM | 5.3 | 0.1% | Jun 10, 2026 | OpenFGA is an authorization/permission engine built for developers. Prior to version 1.16.0, when iterator caching is en... |
| CVE-2026-45566 | MEDIUM | 6.1 | 0.2% | Jun 10, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th... |
| CVE-2026-7516 | MEDIUM | 5.1 | 0.2% | Jun 10, 2026 | A vulnerability was identified in the Lenovo Android Application, distributed exclusively on tablets in the Chinese mark... |
| CVE-2026-53474 | MEDIUM | 6.5 | 0.3% | Jun 10, 2026 | A flaw was found in migration-planner. A remote authenticated attacker could exploit this vulnerability by uploading a s... |
| CVE-2026-53473 | MEDIUM | 5.4 | 0.2% | Jun 10, 2026 | A flaw was found in migration-planner-ui-app. An attacker can register a malicious discovery agent with a specially craf... |
| CVE-2026-45563 | MEDIUM | 4.3 | 0.2% | Jun 10, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, GE... |
| CVE-2026-45561 | MEDIUM | 6.5 | 0.2% | Jun 10, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, th... |
| CVE-2026-45560 | MEDIUM | 6.1 | 0.1% | Jun 10, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, wr... |
| CVE-2026-45559 | MEDIUM | 4.9 | 0.2% | Jun 10, 2026 | Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ge... |
| CVE-2026-11884 | MEDIUM | 6.5 | 0.4% | Jun 10, 2026 | A heap buffer overflow flaw was found in 389 Directory Server. When serializing objectclass definitions, the oc_superior... |
| CVE-2026-53442 | MEDIUM | 5.3 | 0.2% | Jun 10, 2026 | Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not encrypt secrets from POST config.xml submissions before stor... |
| CVE-2026-53441 | MEDIUM | 5.4 | 0.3% | Jun 10, 2026 | Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-prov... |
| CVE-2026-53440 | MEDIUM | 4.3 | 0.2% | Jun 10, 2026 | Jenkins 2.567 and earlier, LTS 2.555.2 and earlier does not ensure that the "from" parameter in the "Delegate to servlet... |
| CVE-2026-53439 | MEDIUM | 4.3 | 0.2% | Jun 10, 2026 | Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permis... |
| CVE-2026-53438 | MEDIUM | 4.3 | 0.2% | Jun 10, 2026 | A missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allows attackers with Item/Cancel permi... |
| CVE-2026-53437 | MEDIUM | 4.3 | 0.4% | Jun 10, 2026 | Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately... |
| CVE-2026-53436 | MEDIUM | 4.3 | 0.3% | Jun 10, 2026 | Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately... |
| CVE-2026-52759 | MEDIUM | 6.7 | 0.2% | Jun 10, 2026 | Ghidra before 12.1.1 contains an uncontrolled memory allocation vulnerability in the Mach-O binary parser that allows at... |
| CVE-2026-52757 | MEDIUM | 4.6 | 0.1% | Jun 10, 2026 | Ghidra before 12.1 contains a heap-use-after-free vulnerability in the decompiler's HighVariable::merge() function durin... |
| CVE-2026-52756 | MEDIUM | 6.5 | 0.5% | Jun 10, 2026 | Ghidra before 12.2 contains an unauthenticated path traversal vulnerability in the IsfServer that accepts TCP connection... |
| CVE-2026-52753 | MEDIUM | 6.7 | 0.2% | Jun 10, 2026 | Ghidra before 12.0.3 contains an out-of-memory vulnerability in the rust_demangle function that allocates unbounded outp... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now