2026 CVE Vulnerabilities
47,998 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13759 | HIGH | 8.8 | 0.3% | Jun 30, 2026 | IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, Objec... |
| CVE-2026-12084 | HIGH | 7.5 | 0.1% | Jun 30, 2026 | IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 uses Cross-Origin Resource Sharing (CORS) which... |
| CVE-2026-11806 | HIGH | 7.5 | 0.5% | Jun 30, 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability... |
| CVE-2026-11595 | HIGH | 7.5 | 0.3% | Jun 30, 2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the adm... |
| CVE-2026-10564 | HIGH | 8.2 | 0.2% | Jun 30, 2026 | IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderComponent in rss... |
| CVE-2026-10129 | HIGH | 8.5 | 0.2% | Jun 30, 2026 | IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerability in th... |
| CVE-2026-10513 | HIGH | 7.2 | 0.2% | Jun 30, 2026 | The Webmention plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.8.0 v... |
| CVE-2026-9263 | HIGH | 8.1 | 0.2% | Jun 30, 2026 | The Zephyr Bluetooth controller ISO Adaptation Layer (subsys/bluetooth/controller/ll_sw/isoal.c) fails to validate the l... |
| CVE-2026-8864 | HIGH | 7.3 | 0.1% | Jun 30, 2026 | The HP Fan Control App might allow local escalation of privileges. An updated version of HP Fan Control App has been rel... |
| CVE-2026-58377 | HIGH | 8.6 | 0.3% | Jun 30, 2026 | JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to ... |
| CVE-2026-58376 | HIGH | 7.6 | 0.2% | Jun 30, 2026 | Dolibarr through 23.0.3, fixed in commit 14db36e, contains a sql injection vulnerability that allows authenticated API u... |
| CVE-2026-58375 | HIGH | 8.7 | 0.5% | Jun 30, 2026 | JimuReport through 2.5.0 exposes the POST /jmreport/auto/export endpoint without authentication: the handler is annotate... |
| CVE-2026-58372 | HIGH | 8.1 | 0.8% | Jun 30, 2026 | SeaweedFS before 4.34 contains a path traversal vulnerability in the S3 gateway DeleteMultipleObjectsHandler that allows... |
| CVE-2026-58176 | HIGH | 7.1 | 0.3% | Jun 30, 2026 | RuoYi-Vue-Plus through 5.6.2, fixed in commit 88d03d9, exposes workflow task management endpoints under /workflow/task (... |
| CVE-2026-58170 | HIGH | 8.3 | 0.4% | Jun 30, 2026 | Vibe-Trading before 0.1.10 builds the proposal file path by joining a caller-supplied proposal identifier onto the broke... |
| CVE-2026-58169 | HIGH | 7.7 | 0.3% | Jun 30, 2026 | Vibe-Trading before 0.1.10 contains a DNS rebinding authentication bypass vulnerability that allows remote attackers to ... |
| CVE-2026-58168 | HIGH | 8.8 | 0.4% | Jun 30, 2026 | DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke... |
| CVE-2026-58167 | HIGH | 7.1 | 0.2% | Jun 30, 2026 | Nightingale (n9e) before 9.0.0-beta.2 exposes full datasource configurations, including plaintext database passwords, HT... |
| CVE-2026-58165 | HIGH | 8.8 | 0.2% | Jun 30, 2026 | OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated... |
| CVE-2026-49451 | HIGH | 7.5 | 0.7% | Jun 30, 2026 | The OpenAPI.NET SDK contains a useful object model for OpenAPI documents in .NET along with common serializers to extrac... |
| CVE-2026-10653 | HIGH | 8.1 | 0.3% | Jun 30, 2026 | The Zephyr net_buf library (lib/net_buf/buf.c) manipulated both of its reference counts -- the per-header buf->ref and t... |
| CVE-2026-10652 | HIGH | 7.4 | 0.3% | Jun 30, 2026 | Zephyr's DNS resolver (subsys/net/lib/dns) parses resource records from DNS responses in dns_unpack_answer(), which vali... |
| CVE-2026-48307 | HIGH | 8.8 | 0.3% | Jun 30, 2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An... |
| CVE-2026-48285 | HIGH | 8.6 | — | Jun 30, 2026 | ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that ... |
| CVE-2026-44949 | HIGH | 7 | 0.2% | Jun 30, 2026 | A Rancher FleetWorkspace admission path allowed side effects to occur in the Rancher webhook handler for versions 0.7.0... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now