2026 CVE Vulnerabilities
45,891 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49496 | MEDIUM | 6.9 | 0.2% | Jun 10, 2026 | Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator ... |
| CVE-2026-49495 | MEDIUM | 6.7 | 0.2% | Jun 10, 2026 | Ghidra 10.2 before 12.1 contains an uncontrolled resource consumption vulnerability in ExportTrie.parseTrie() that lacks... |
| CVE-2026-11853 | MEDIUM | 6.5 | 0.3% | Jun 10, 2026 | Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages... |
| CVE-2026-11852 | MEDIUM | 6.5 | 0.2% | Jun 10, 2026 | Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debus... |
| CVE-2026-9019 | MEDIUM | 6.4 | 0.2% | Jun 10, 2026 | The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderCol... |
| CVE-2026-8853 | MEDIUM | 4.4 | 0.2% | Jun 10, 2026 | The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all version... |
| CVE-2026-8613 | MEDIUM | 6.4 | 0.2% | Jun 10, 2026 | The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widge... |
| CVE-2026-29115 | MEDIUM | 6.9 | 0.4% | Jun 10, 2026 | A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially c... |
| CVE-2026-11815 | MEDIUM | 5.3 | 0.3% | Jun 10, 2026 | An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could pote... |
| CVE-2026-24720 | MEDIUM | 6.5 | 0.3% | Jun 10, 2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 6. If a r... |
| CVE-2026-24717 | MEDIUM | 6.5 | 0.4% | Jun 10, 2026 | A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker ... |
| CVE-2026-22899 | MEDIUM | 6.5 | 0.3% | Jun 10, 2026 | A NULL pointer dereference vulnerability has been reported to affect File Station 6. If a remote attacker gains a user a... |
| CVE-2026-46532 | MEDIUM | 4.6 | 0.2% | Jun 10, 2026 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.3, and 6.0... |
| CVE-2026-45329 | MEDIUM | 6.5 | 0.1% | Jun 10, 2026 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secu... |
| CVE-2026-45160 | MEDIUM | 6.5 | 0.2% | Jun 10, 2026 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5.4.4, 5.5.4, and 6.0... |
| CVE-2026-46546 | MEDIUM | 5.4 | 0.1% | Jun 10, 2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version ... |
| CVE-2026-53675 | MEDIUM | 5.3 | 0.2% | Jun 10, 2026 | BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any aut... |
| CVE-2026-46543 | MEDIUM | 5.3 | 0.3% | Jun 10, 2026 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to... |
| CVE-2026-46542 | MEDIUM | 4.3 | 0.2% | Jun 10, 2026 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to... |
| CVE-2026-46540 | MEDIUM | 6.5 | 0.3% | Jun 10, 2026 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to... |
| CVE-2026-46539 | MEDIUM | 5.9 | 0.1% | Jun 10, 2026 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to... |
| CVE-2026-46411 | MEDIUM | 6.5 | 0.3% | Jun 10, 2026 | FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.2, authorized clients have t... |
| CVE-2026-44505 | MEDIUM | 5.3 | 0.3% | Jun 10, 2026 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. network-... |
| CVE-2026-41837 | MEDIUM | 5.3 | 0.2% | Jun 10, 2026 | Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and... |
| CVE-2026-41730 | MEDIUM | 5.3 | 0.2% | Jun 10, 2026 | Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persist... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now