2026 CVE Vulnerabilities
46,851 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12015 | MEDIUM | 5.3 | 0.2% | Jun 11, 2026 | Use after free in Autofill in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the re... |
| CVE-2026-53818 | MEDIUM | 6.9 | 0.1% | Jun 11, 2026 | OpenClaw before 2026.4.24 contains an authorization bypass vulnerability in the MCP loopback feature that allows non-own... |
| CVE-2026-53809 | MEDIUM | 4.8 | 0.1% | Jun 11, 2026 | OpenClaw before 2026.4.25 contains a policy bypass vulnerability in embedded runner policy that allows requests using pr... |
| CVE-2026-53808 | MEDIUM | 6.5 | 0.2% | Jun 11, 2026 | OpenClaw before 2026.5.6 contains an approval policy bypass vulnerability in the Skill Workshop apply flow that allows a... |
| CVE-2026-53781 | MEDIUM | 5.3 | 0.3% | Jun 11, 2026 | Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhausti... |
| CVE-2026-49949 | MEDIUM | 6 | 0.3% | Jun 11, 2026 | CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercep... |
| CVE-2026-45802 | MEDIUM | 6 | 0.3% | Jun 11, 2026 | FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as template... |
| CVE-2026-53702 | MEDIUM | 6.5 | 0.2% | Jun 11, 2026 | A stack buffer overflow flaw was found in the GStreamer H.265 codec parser library (gst-plugins-bad). When parsing a buf... |
| CVE-2026-53701 | MEDIUM | 6.5 | 0.2% | Jun 11, 2026 | An out-of-bounds write vulnerability was found in GStreamer's H.266/VVC PPS picture partition parser in gst-plugins-bad.... |
| CVE-2026-47250 | MEDIUM | 6.1 | 0.3% | Jun 11, 2026 | mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.7.0, the ... |
| CVE-2026-47177 | MEDIUM | 5.7 | 0.3% | Jun 11, 2026 | Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, a use... |
| CVE-2026-47176 | MEDIUM | 5.7 | 0.3% | Jun 11, 2026 | Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, a use... |
| CVE-2026-47173 | MEDIUM | 6.3 | 0.3% | Jun 11, 2026 | Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a nor... |
| CVE-2026-47167 | MEDIUM | 5.3 | 0.1% | Jun 11, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0496, a code injection vulnerability exists in s:s... |
| CVE-2026-47157 | MEDIUM | 6.5 | 0.2% | Jun 11, 2026 | aiograpi is an asynchronous Instagram API for Python. aiograpi versions before 0.9.10 accepted server-supplied signup ch... |
| CVE-2026-46698 | MEDIUM | 5.3 | 0.2% | Jun 11, 2026 | Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.9, Fediverse Embeds registered the unau... |
| CVE-2026-11986 | MEDIUM | 4.9 | 0.3% | Jun 11, 2026 | A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabi... |
| CVE-2026-44489 | MEDIUM | 5.3 | 0.2% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created b... |
| CVE-2026-4096 | MEDIUM | 6.1 | 0.1% | Jun 11, 2026 | IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by th... |
| CVE-2026-3341 | MEDIUM | 5.4 | 0.1% | Jun 11, 2026 | IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allo... |
| CVE-2026-6338 | MEDIUM | 4.9 | 0.3% | Jun 11, 2026 | A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13... |
| CVE-2026-53723 | MEDIUM | 5.8 | 0.2% | Jun 11, 2026 | Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to descri... |
| CVE-2026-49214 | MEDIUM | 5.3 | 0.2% | Jun 11, 2026 | guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII con... |
| CVE-2026-48998 | MEDIUM | 5.3 | 0.2% | Jun 11, 2026 | guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host he... |
| CVE-2026-11956 | MEDIUM | 6.3 | 0.2% | Jun 11, 2026 | A vulnerability was determined in TwiN gatus 5.36.0. Impacted is the function setSessionCookie of the file security/oidc... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now