2026 CVE Vulnerabilities
46,924 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47106 | MEDIUM | 5.4 | 0.2% | Jun 9, 2026 | Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a stored cross-site scripting vulnerabili... |
| CVE-2026-32856 | MEDIUM | 6.1 | 0.2% | Jun 9, 2026 | Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a reflected cross-site scripting vulnerab... |
| CVE-2026-40639 | MEDIUM | 5.7 | 0.1% | Jun 9, 2026 | Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical... |
| CVE-2026-39170 | MEDIUM | 6.3 | 0.1% | Jun 9, 2026 | SemCms 5.0 is vulnerable to Cross Site Request Forgery (CSRF) via crafted POST request to /admin/semcms_user.php. |
| CVE-2026-36798 | MEDIUM | 6.5 | 0.3% | Jun 9, 2026 | Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain multiple stack overflows in the formSet... |
| CVE-2026-36778 | MEDIUM | 4.9 | 0.4% | Jun 9, 2026 | Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain a stack overflow in... |
| CVE-2026-36777 | MEDIUM | 6.5 | 0.2% | Jun 9, 2026 | Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in... |
| CVE-2026-36773 | MEDIUM | 6.5 | 0.2% | Jun 9, 2026 | Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in... |
| CVE-2026-36772 | MEDIUM | 6.5 | 0.2% | Jun 9, 2026 | Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in... |
| CVE-2026-36728 | MEDIUM | 5.4 | 0.2% | Jun 9, 2026 | A markdown based cross-site scripting (XSS) vulnerability in the AI assistant chat function of FastapiAdmin v2.2.0 allow... |
| CVE-2026-36726 | MEDIUM | 5.3 | 0.5% | Jun 9, 2026 | An arbitrary file deletion vulnerability in the /api/delete-temp-license/{file} endpoint of bookcars v8.3 allows unauthe... |
| CVE-2026-36725 | MEDIUM | 6.1 | 0.2% | Jun 9, 2026 | A markdown based cross-site scripting (XSS) vulnerability in the /system/notice/create endpoint of FastapiAdmin v2.2.0 a... |
| CVE-2026-36724 | MEDIUM | 6.5 | 0.3% | Jun 9, 2026 | An uncaught exception in the /application/job/update/{id} endpoint of FastapiAdmin v2.2.0 allows authenticated attackers... |
| CVE-2026-36722 | MEDIUM | 5.4 | 0.2% | Jun 9, 2026 | An authenticated arbitrary file upload vulnerability in the /api/create-car-image component of bookcars v8.3 allows atta... |
| CVE-2026-44275 | MEDIUM | 6.3 | 0.1% | Jun 9, 2026 | Dell/Alienware Purchased Apps, versions prior to 1.1.32.0, contain an Improper Link Resolution Before File Access ('Link... |
| CVE-2026-41116 | MEDIUM | 6.3 | 0.1% | Jun 9, 2026 | Dell Inventory Collector Client, versions prior to 13.8.0, contain an Improper Link Resolution Before File Access ('Link... |
| CVE-2026-34705 | MEDIUM | 5.5 | 0.2% | Jun 9, 2026 | InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds read vulnerability that could lead t... |
| CVE-2026-34704 | MEDIUM | 5.5 | 0.1% | Jun 9, 2026 | InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could r... |
| CVE-2026-34703 | MEDIUM | 5.5 | 0.1% | Jun 9, 2026 | InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could r... |
| CVE-2026-34694 | MEDIUM | 4.8 | 0.2% | Jun 9, 2026 | Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting ... |
| CVE-2026-28237 | MEDIUM | 5.5 | 0.1% | Jun 9, 2026 | Unrestricted resource allocation in AMD uProf may be exploitable to consume excessive system resources, potentially lead... |
| CVE-2026-0466 | MEDIUM | 5.5 | 0.1% | Jun 9, 2026 | Improper access control in AMD uProf may allow a local attacker with user privileges to write to the kernel-shared memor... |
| CVE-2026-9210 | MEDIUM | 4.5 | 0.2% | Jun 9, 2026 | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t... |
| CVE-2026-50507 | MEDIUM | 6.8 | 5.0% | Jun 9, 2026 | Missing authentication for critical function in Windows BitLocker allows an unauthorized attacker to bypass a security f... |
| CVE-2026-49958 | MEDIUM | 5 | 0.1% | Jun 9, 2026 | Hermes WebUI before version 0.51.303 contains a time-of-check time-of-use (TOCTOU) race condition vulnerability in the g... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now