2026 CVE Vulnerabilities
47,534 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6239 | MEDIUM | 6.8 | 0.2% | Jun 6, 2026 | A stack‑based buffer overflow vulnerability exists in Tapo C520WS v2 in the ONVIF CreateUsers service, where the device ... |
| CVE-2026-10038 | MEDIUM | 4.3 | 0.3% | Jun 6, 2026 | The Charitable – Donation Plugin for WordPress – Fundraising with Recurring Donations & More plugin for WordPress is vul... |
| CVE-2026-7523 | MEDIUM | 4.3 | 0.3% | Jun 5, 2026 | The Alba Board plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. T... |
| CVE-2026-45409 | MEDIUM | 5.3 | 0.4% | Jun 5, 2026 | Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in ... |
| CVE-2026-46401 | MEDIUM | 5.3 | 0.3% | Jun 5, 2026 | HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.0 suffer from an improper se... |
| CVE-2026-46397 | MEDIUM | 6.5 | 0.3% | Jun 5, 2026 | HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an Authenticated Local Fil... |
| CVE-2026-46357 | MEDIUM | 6.5 | 0.2% | Jun 5, 2026 | HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the HAX CMS NodeJS applica... |
| CVE-2026-45778 | MEDIUM | 5.4 | 0.1% | Jun 5, 2026 | OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, an authenticated attac... |
| CVE-2026-45776 | MEDIUM | 4.3 | 0.2% | Jun 5, 2026 | OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, a flaw in Open XDMoD's... |
| CVE-2026-25624 | MEDIUM | 4.8 | 0.2% | Jun 5, 2026 | An administrative cross-site scripting (XSS) vulnerability exists in the web user interface dashboard layout of Arista E... |
| CVE-2026-46390 | MEDIUM | 6.9 | 0.3% | Jun 5, 2026 | HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 2.0.0 and prior to version 26.0... |
| CVE-2026-11341 | MEDIUM | 6.3 | 1.0% | Jun 5, 2026 | A flaw has been found in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_412DA0 of the file /boaf... |
| CVE-2026-8714 | MEDIUM | 6.5 | 0.2% | Jun 5, 2026 | A denial-of-service vulnerability exists in the RTSP server component of TP-Link Tapo C520WS v2 due to improper handling... |
| CVE-2026-7473 | MEDIUM | 6.9 | 0.8% | Jun 5, 2026 | On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LA... |
| CVE-2026-48112 | MEDIUM | 6.5 | 0.3% | Jun 5, 2026 | 7-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain a heap out-of-bounds read in... |
| CVE-2026-48104 | MEDIUM | 4.2 | 0.2% | Jun 5, 2026 | 7-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain an uninitialized heap read i... |
| CVE-2026-11337 | MEDIUM | 4.3 | 0.3% | Jun 5, 2026 | A vulnerability was found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e... |
| CVE-2026-48102 | MEDIUM | 4.3 | 0.2% | Jun 5, 2026 | 7-Zip is a file archiver with a high compression ratio. Versions 9.11 through 26.00 contain a heap out-of-bounds read of... |
| CVE-2026-48101 | MEDIUM | 6.5 | 0.3% | Jun 5, 2026 | 7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an An uninitialized memory d... |
| CVE-2026-11336 | MEDIUM | 6.3 | 0.2% | Jun 5, 2026 | A vulnerability has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a388529... |
| CVE-2026-38579 | MEDIUM | 6.1 | 0.2% | Jun 5, 2026 | Multiple reflected Cross-Site Scripting (XSS) vulnerabilities in damasac thaipalliative_lte through version 3.0 allow re... |
| CVE-2026-37737 | MEDIUM | 6.5 | 0.2% | Jun 5, 2026 | sanic-cors version 2.2.0 and prior contains an improper regular expression in the try_match() function in sanic_cors/cor... |
| CVE-2026-11335 | MEDIUM | 6.3 | 0.2% | Jun 5, 2026 | A flaw has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae... |
| CVE-2026-11333 | MEDIUM | 6.3 | 0.2% | Jun 5, 2026 | A security vulnerability has been detected in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a... |
| CVE-2026-50235 | MEDIUM | 6.1 | 0.2% | Jun 5, 2026 | Lyrion Music Server 9.2.0 contains a reflected cross-site scripting vulnerability in advanced search parameters that fai... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now