2026 CVE Vulnerabilities
48,012 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56285 | HIGH | 8.6 | 0.4% | Jun 29, 2026 | Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded defaul... |
| CVE-2026-36848 | HIGH | 7.5 | 0.7% | Jun 29, 2026 | Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem. |
| CVE-2026-13592 | HIGH | 7.3 | 0.4% | Jun 29, 2026 | A vulnerability was detected in liftoff-sr CIPster up to e8e9dba09bf56962807d3504b783ccdb6287f3e4. Affected by this issu... |
| CVE-2026-13752 | HIGH | 8 | 0.1% | Jun 29, 2026 | Improper neutralization of parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. An attac... |
| CVE-2026-12912 | HIGH | 7.3 | 0.2% | Jun 29, 2026 | A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLo... |
| CVE-2026-41052 | HIGH | 8.8 | 0.3% | Jun 29, 2026 | Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2... |
| CVE-2026-13749 | HIGH | 8.8 | 0.4% | Jun 29, 2026 | Improper neutralization in the Snowpark annotation processor callback template in Snowflake CLI versions prior to 3.19 a... |
| CVE-2026-13744 | HIGH | 8.8 | 0.3% | Jun 29, 2026 | Improper neutralization of attacker-controlled content in Snowflake CLI versions prior to 3.19 allowed unintended SQL ex... |
| CVE-2026-13583 | HIGH | 8.8 | 0.4% | Jun 29, 2026 | A vulnerability has been found in Edimax EW-7478APC 1.04. Impacted is the function formUSBFolder of the file /goform/for... |
| CVE-2026-13582 | HIGH | 8.8 | — | Jun 29, 2026 | A flaw has been found in Edimax EW-7478APC 1.04. This issue affects the function formUSBAccount of the file /goform/form... |
| CVE-2026-13580 | HIGH | 8.8 | — | Jun 29, 2026 | A security vulnerability has been detected in Edimax EW-7478APC 1.04. This affects the function formQoS of the file /gof... |
| CVE-2026-57338 | HIGH | 7.1 | — | Jun 29, 2026 | Unauthenticated Cross Site Scripting (XSS) in ARForms <= 7.1.2 versions. |
| CVE-2026-57337 | HIGH | 7.1 | — | Jun 29, 2026 | Unauthenticated Cross Site Scripting (XSS) in Landing Page Builder <= 1.5.3.5 versions. |
| CVE-2026-57336 | HIGH | 7.1 | — | Jun 29, 2026 | Unauthenticated Cross Site Scripting (XSS) in Jobify <= 4.3.2 versions. |
| CVE-2026-57333 | HIGH | 7.1 | — | Jun 29, 2026 | Unauthenticated Cross Site Scripting (XSS) in Link Whisper Free <= 0.9.4 versions. |
| CVE-2026-57332 | HIGH | 7.1 | — | Jun 29, 2026 | Subscriber Broken Access Control in Wallet System for WooCommerce <= 2.7.6 versions. |
| CVE-2026-57320 | HIGH | 7.1 | — | Jun 29, 2026 | Unauthenticated Cross Site Scripting (XSS) in BEAR <= 1.1.8 versions. |
| CVE-2026-56124 | HIGH | 8.7 | 0.4% | Jun 29, 2026 | phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers t... |
| CVE-2026-55844 | HIGH | 7.5 | 0.2% | Jun 29, 2026 | Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The... |
| CVE-2026-55607 | HIGH | 8.8 | 0.7% | Jun 29, 2026 | Claude Code is an agentic coding tool. From 2.1.38 until 2.1.163, Claude Code's worktree handling allowed creation of w... |
| CVE-2026-49049 | HIGH | 7.5 | 0.2% | Jun 29, 2026 | The Helix3 plugin for Joomla exposes an ajax handler task, that allows unauthenticated attackers to delete arbitrary fil... |
| CVE-2026-54371 | HIGH | 7.1 | 0.1% | Jun 29, 2026 | attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows ... |
| CVE-2026-54370 | HIGH | 7.2 | — | Jun 29, 2026 | acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local... |
| CVE-2026-54369 | HIGH | 7.1 | 0.2% | Jun 29, 2026 | acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(... |
| CVE-2026-40524 | HIGH | 8.1 | 0.3% | Jun 29, 2026 | FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the get_gl_transactions() function where the fil... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now