2026 CVE Vulnerabilities
46,946 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46329 | MEDIUM | 5.5 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: erofs: handle end of filesystem properly for file-b... |
| CVE-2026-11793 | MEDIUM | 4.9 | 0.3% | Jun 9, 2026 | A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-co... |
| CVE-2026-11790 | MEDIUM | 4.9 | 0.3% | Jun 9, 2026 | A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password storage plugin does not enforce an upper bound on t... |
| CVE-2026-11789 | MEDIUM | 6.5 | 0.3% | Jun 9, 2026 | A flaw was found in 389 Directory Server. The SMD5 password storage plugin performs unsigned integer underflow when comp... |
| CVE-2026-11787 | MEDIUM | 6.3 | 0.2% | Jun 9, 2026 | A flaw was found in 389 Directory Server. The ldap_utf8prev() function reads bytes before the start of a buffer without ... |
| CVE-2026-11786 | MEDIUM | 6.5 | 0.2% | Jun 9, 2026 | A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute ... |
| CVE-2026-11785 | MEDIUM | 4.3 | 0.2% | Jun 9, 2026 | A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial st... |
| CVE-2026-46318 | MEDIUM | 5.5 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: Revert "mm/hugetlbfs: update hugetlbfs to use mmap_... |
| CVE-2026-49740 | MEDIUM | 6.3 | 0.2% | Jun 9, 2026 | TYPO3's cache frontend (VariableFrontend) and persistent key-value store (Registry) deserialized PHP payloads without in... |
| CVE-2026-47352 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | Authenticated backend users were able to retrieve file metadata via several Backend API routes without proper permission... |
| CVE-2026-47351 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | Backend users were able to insert arbitrary records and files into the TYPO3 clipboard without proper read permission ch... |
| CVE-2026-47350 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | Backend users were able to move records to a different page without having edit permissions on the source page. This iss... |
| CVE-2026-47349 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | Backend users with access to the Recycler module were able to restore soft-deleted records on pages or for tables they w... |
| CVE-2026-47348 | MEDIUM | 5.1 | 0.3% | Jun 9, 2026 | Editors with access to create or modify page content were able to include HTML markup in page titles that were stored in... |
| CVE-2026-47347 | MEDIUM | 5.3 | 0.3% | Jun 9, 2026 | Applications that use GeneralUtility::sanitizeLocalUrl to allow only local URLs are vulnerable to open redirect attacks ... |
| CVE-2026-52902 | MEDIUM | 4.7 | 0.1% | Jun 9, 2026 | A path traversal vulnerability was found in awxkit, the CLI tool for AWX. The YAML !include directive does not sanitize ... |
| CVE-2026-4058 | MEDIUM | 4.3 | 0.2% | Jun 9, 2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP... |
| CVE-2026-46747 | MEDIUM | 5.3 | 0.2% | Jun 9, 2026 | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected application does not p... |
| CVE-2026-8677 | MEDIUM | 6.4 | 0.2% | Jun 9, 2026 | The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stored... |
| CVE-2026-8599 | MEDIUM | 6.4 | 0.2% | Jun 9, 2026 | The MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable ... |
| CVE-2026-7542 | MEDIUM | 6.5 | 0.3% | Jun 9, 2026 | The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions 7.0 to 7.0.10. ... |
| CVE-2026-6899 | MEDIUM | 5.6 | 0.1% | Jun 9, 2026 | Check for certificate revocation only considers the first matching CRL and ignores other valid CRLs of the same CA in th... |
| CVE-2026-49818 | MEDIUM | 6.5 | 0.7% | Jun 9, 2026 | The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a c... |
| CVE-2026-46315 | MEDIUM | 5.5 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: io_uring/waitid: clear waitid info before copying i... |
| CVE-2026-34905 | MEDIUM | 6.5 | 0.3% | Jun 9, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache An... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now