2026 CVE Vulnerabilities
48,008 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-34594 | HIGH | 8.8 | 1.1% | Jun 29, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-57919 | HIGH | 7.8 | 0.1% | Jun 29, 2026 | PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DA... |
| CVE-2026-56018 | HIGH | 7.5 | 0.6% | Jun 29, 2026 | JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every call to minify(), allowing unbounded memory ... |
| CVE-2026-56017 | HIGH | 7.5 | 0.5% | Jun 29, 2026 | JavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL pointer dereference when the first meaningful t... |
| CVE-2026-53426 | HIGH | 8.2 | 0.1% | Jun 29, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in leandrocp MDEx allows Excessive Allocation. MDEx.... |
| CVE-2026-43735 | HIGH | 8.1 | 0.3% | Jun 29, 2026 | The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS ... |
| CVE-2026-43731 | HIGH | 8.8 | 0.3% | Jun 29, 2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 18.7.10 ... |
| CVE-2026-43725 | HIGH | 7.1 | 0.8% | Jun 29, 2026 | The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.... |
| CVE-2026-43724 | HIGH | 7.8 | 0.3% | Jun 29, 2026 | The issue was addressed with improved input sanitization. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.... |
| CVE-2026-43715 | HIGH | 8.8 | 0.8% | Jun 29, 2026 | A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 a... |
| CVE-2026-43705 | HIGH | 8.8 | 0.4% | Jun 29, 2026 | A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS ... |
| CVE-2026-43701 | HIGH | 7.1 | 0.5% | Jun 29, 2026 | The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 18.7.10 and iPadOS 18.7.10, iOS ... |
| CVE-2026-58000 | HIGH | 8.8 | 1.4% | Jun 29, 2026 | luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKe... |
| CVE-2026-57999 | HIGH | 8.8 | 1.2% | Jun 29, 2026 | luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that allows... |
| CVE-2026-57960 | HIGH | 8.3 | 0.3% | Jun 29, 2026 | Hi.Events through 1.9.0 public check-in list endpoints use short_id as sole access control, allowing unauthenticated acc... |
| CVE-2026-57959 | HIGH | 8.2 | 0.2% | Jun 29, 2026 | Hi.Events through 1.9.0 contains a promo code validation vulnerability where reservation validates usage count before as... |
| CVE-2026-57955 | HIGH | 8.5 | 0.2% | Jun 29, 2026 | SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary C... |
| CVE-2026-57951 | HIGH | 7.1 | 0.2% | Jun 29, 2026 | Mythic before 3.4.0.60 contains a broken hasura permission filter on the payload_build_step table with an always-satisfi... |
| CVE-2026-57950 | HIGH | 8.6 | 0.3% | Jun 29, 2026 | ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control vulnerability in ErpSaleOrderCon... |
| CVE-2026-57949 | HIGH | 7.1 | 0.2% | Jun 29, 2026 | ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module... |
| CVE-2026-57948 | HIGH | 7.6 | 0.1% | Jun 29, 2026 | Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the... |
| CVE-2026-57947 | HIGH | 8.5 | 0.2% | Jun 29, 2026 | Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that al... |
| CVE-2026-56783 | HIGH | 7.1 | 0.3% | Jun 29, 2026 | Parseable before 2.9.2 contains an information disclosure vulnerability in the notification-target API endpoints that re... |
| CVE-2026-56780 | HIGH | 7.7 | 0.3% | Jun 29, 2026 | Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/passwor... |
| CVE-2026-56285 | HIGH | 8.6 | 0.4% | Jun 29, 2026 | Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded defaul... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now