2026 CVE Vulnerabilities
48,008 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-50750 | HIGH | 7.5 | 0.5% | Jun 30, 2026 | Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Foll... |
| CVE-2026-50734 | HIGH | 7.5 | 0.5% | Jun 30, 2026 | Memory Allocation with Excessive Size Value vulnerability in Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ Al... |
| CVE-2026-49877 | HIGH | 8.1 | 0.4% | Jun 30, 2026 | Improper Authorization vulnerability in Apache ActiveMQ. An authenticated low-privilege Web Console user by default can... |
| CVE-2026-49434 | HIGH | 7.5 | 0.4% | Jun 30, 2026 | Improper Input Validation vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. An attacker th... |
| CVE-2026-49432 | HIGH | 7.5 | 0.5% | Jun 30, 2026 | Improper Input Validation vulnerability in Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp. A remote unauth... |
| CVE-2026-8141 | HIGH | 7.2 | 0.3% | Jun 30, 2026 | The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_include... |
| CVE-2026-13149 | HIGH | 7.7 | 0.4% | Jun 30, 2026 | brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time comple... |
| CVE-2026-10763 | HIGH | 7 | 0.3% | Jun 30, 2026 | PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support fr... |
| CVE-2026-12578 | HIGH | 8.4 | 0.4% | Jun 30, 2026 | The affected product is vulnerable to a deserialization of untrusted data, which may allow an attacker to execute arbitr... |
| CVE-2026-56808 | HIGH | 8.6 | 1.6% | Jun 30, 2026 | DGM3103SCT provided by AVTECH Security Corporation contains an OS command injection vulnerability, which may lead to arb... |
| CVE-2026-56137 | HIGH | 8.4 | 0.7% | Jun 30, 2026 | RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If a user loads ... |
| CVE-2026-14164 | HIGH | 7.5 | 0.5% | Jun 30, 2026 | A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive,... |
| CVE-2026-12240 | HIGH | 8 | 0.3% | Jun 30, 2026 | The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat... |
| CVE-2026-11590 | HIGH | 8.6 | 0.2% | Jun 30, 2026 | The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sanitize user-supplied array keys b... |
| CVE-2026-11589 | HIGH | 8.8 | 0.2% | Jun 30, 2026 | The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not properly validate uploaded files, a... |
| CVE-2026-58302 | HIGH | 8.4 | 0.2% | Jun 30, 2026 | rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escalation. It is installed SUID root and loads s... |
| CVE-2026-8023 | HIGH | 7.5 | 0.9% | Jun 29, 2026 | Zephyr's HTTP server (subsys/net/lib/http) provides a static-filesystem resource type (HTTP_RESOURCE_TYPE_STATIC_FS, ava... |
| CVE-2026-51219 | HIGH | 7.5 | 0.3% | Jun 29, 2026 | A heap buffer overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages function of lib60870 v2.3.3 to v2.3.6 allows... |
| CVE-2026-51218 | HIGH | 7.5 | 0.3% | Jun 29, 2026 | A heap buffer overflow in the TS7Worker::PerformFunctionWrite() function (/core/s7_server.cpp) of snap7 v1.4.3 allows at... |
| CVE-2026-51221 | HIGH | 7.5 | 0.2% | Jun 29, 2026 | A buffer overflow in the Get_Attribute_List function of EIPStackGroup OpENer commit 76b95c allows attackers to cause a D... |
| CVE-2026-34592 | HIGH | 7.7 | 0.2% | Jun 29, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-55957 | HIGH | 7.3 | 0.3% | Jun 29, 2026 | Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate... |
| CVE-2026-53404 | HIGH | 7.3 | 0.2% | Jun 29, 2026 | Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first cond... |
| CVE-2026-41896 | HIGH | 7.5 | 0.2% | Jun 29, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-34597 | HIGH | 8.8 | 0.5% | Jun 29, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now