2026 CVE Vulnerabilities
46,944 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34692 | MEDIUM | 5.4 | 0.2% | Jun 9, 2026 | Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by a DOM-based Cross-Site Scripting ... |
| CVE-2026-33113 | MEDIUM | 6.1 | 0.5% | Jun 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo... |
| CVE-2026-28301 | MEDIUM | 4.8 | 0.2% | Jun 9, 2026 | A vulnerability in which an attacker can provide a crafted external URL that may redirect a user to an unintended websit... |
| CVE-2026-0420 | MEDIUM | 5.9 | 0.1% | Jun 9, 2026 | An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which co... |
| CVE-2026-0418 | MEDIUM | 4.5 | 0.2% | Jun 9, 2026 | Insufficient configuration management in the listed devices allows authenticated administrators connected to the local n... |
| CVE-2026-0417 | MEDIUM | 4.5 | 0.2% | Jun 9, 2026 | Insufficient input validation vulnerability in the listed NETGEAR devices allows authenticated administrators connected ... |
| CVE-2026-0416 | MEDIUM | 4.5 | 0.2% | Jun 9, 2026 | An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated admini... |
| CVE-2026-0415 | MEDIUM | 4.5 | 0.2% | Jun 9, 2026 | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t... |
| CVE-2026-0414 | MEDIUM | 4.5 | 0.2% | Jun 9, 2026 | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t... |
| CVE-2026-0413 | MEDIUM | 4.5 | 0.3% | Jun 9, 2026 | A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated a... |
| CVE-2026-0412 | MEDIUM | 4.5 | 0.2% | Jun 9, 2026 | Insufficient input validation vulnerability in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in ... |
| CVE-2026-0410 | MEDIUM | 4.5 | 0.2% | Jun 9, 2026 | Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorize... |
| CVE-2026-0409 | MEDIUM | 6.4 | 0.3% | Jun 9, 2026 | A NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traffic between the rout... |
| CVE-2026-8045 | MEDIUM | 6.5 | 0.2% | Jun 9, 2026 | CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosu... |
| CVE-2026-49938 | MEDIUM | 6.5 | 0.2% | Jun 9, 2026 | A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, Fo... |
| CVE-2026-52905 | MEDIUM | 5.5 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: disallow non-power of two min_region... |
| CVE-2026-52904 | MEDIUM | 5.5 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/nouveau: fix nvkm_device leak on aperture remov... |
| CVE-2026-49762 | MEDIUM | 5.1 | 0.2% | Jun 9, 2026 | Uncontrolled Resource Consumption vulnerability in the Elixir standard library's Version module allows an attacker who c... |
| CVE-2026-47901 | MEDIUM | 4.6 | 0.1% | Jun 9, 2026 | Logseq is vulnerable to a sandbox escape flaw where plugins running in sandboxed iframes can inject arbitrary HTML attri... |
| CVE-2026-47900 | MEDIUM | 4.6 | 0.1% | Jun 9, 2026 | Logseq is vulnerable to a stored cross-site scripting (XSS). A malicious plugin can include a JavaScript payload in the ... |
| CVE-2026-46329 | MEDIUM | 5.5 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: erofs: handle end of filesystem properly for file-b... |
| CVE-2026-11793 | MEDIUM | 4.9 | 0.3% | Jun 9, 2026 | A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-co... |
| CVE-2026-11790 | MEDIUM | 4.9 | 0.3% | Jun 9, 2026 | A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on t... |
| CVE-2026-11789 | MEDIUM | 6.5 | 0.3% | Jun 9, 2026 | A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when comp... |
| CVE-2026-11787 | MEDIUM | 6.3 | 0.2% | Jun 9, 2026 | A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now