2026 CVE Vulnerabilities
48,018 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8095 | HIGH | 8.1 | 0.4% | Jun 28, 2026 | The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions... |
| CVE-2026-10643 | HIGH | 7.8 | 0.1% | Jun 28, 2026 | Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated the user... |
| CVE-2026-49416 | HIGH | 7.8 | 0.1% | Jun 27, 2026 | The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer ... |
| CVE-2026-49414 | HIGH | 7.8 | 0.1% | Jun 27, 2026 | The ELF image activator cleared per-process ASLR preference flags for setuid binaries after the code that computes the P... |
| CVE-2026-49417 | HIGH | 7 | 0.1% | Jun 27, 2026 | Second, the audio buffer backing a mapping could be freed when the device was closed even though the mapping remained va... |
| CVE-2026-49413 | HIGH | 7.1 | 0.1% | Jun 27, 2026 | The Linuxulator determined whether a binary was set-user-ID or set-group-ID by checking the P_SUGID process flag. Durin... |
| CVE-2026-49412 | HIGH | 7.8 | 0.1% | Jun 27, 2026 | The kernel handler for IPV6_MSFILTER dropped a serializing lock in order to copy the source-filter list from userspace, ... |
| CVE-2026-45258 | HIGH | 7.8 | 0.1% | Jun 27, 2026 | dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length against the... |
| CVE-2026-10820 | HIGH | 8.1 | 0.1% | Jun 27, 2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress pl... |
| CVE-2026-56414 | HIGH | 8.6 | 0.4% | Jun 26, 2026 | A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arb... |
| CVE-2026-55975 | HIGH | 8.6 | 0.7% | Jun 26, 2026 | A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML fields to t... |
| CVE-2026-33560 | HIGH | 8.8 | 0.3% | Jun 26, 2026 | The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which a... |
| CVE-2026-55069 | HIGH | 8.7 | 0.2% | Jun 26, 2026 | Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, this vulnerability exists in the BasicAu... |
| CVE-2026-49984 | HIGH | 7.7 | 0.4% | Jun 26, 2026 | Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage ba... |
| CVE-2026-45807 | HIGH | 7.7 | 0.4% | Jun 26, 2026 | Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.43 and 1.3.19, several Kestra API endpoints ... |
| CVE-2026-36478 | HIGH | 7.5 | 0.4% | Jun 26, 2026 | An issue in Technitium DNS Server v.14.3 and before allows a remote attacker to cause a denial of service via the DnsSer... |
| CVE-2026-54353 | HIGH | 7.1 | 0.2% | Jun 26, 2026 | Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypas... |
| CVE-2026-52884 | HIGH | 7.8 | 0.1% | Jun 26, 2026 | Notepad++ is a free and open-source source code editor. In v8.9.6.1, isInTrustedDirectory() does NOT canonicalize the pa... |
| CVE-2026-50132 | HIGH | 7.3 | 0.2% | Jun 26, 2026 | Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a publi... |
| CVE-2026-48800 | HIGH | 7.8 | 0.4% | Jun 26, 2026 | Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <Command> tag text content inside <UserDef... |
| CVE-2026-48778 | HIGH | 7.8 | 1.4% | Jun 26, 2026 | Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, the <GUIConfig name="commandLineInterpreter"> ... |
| CVE-2026-46710 | HIGH | 7.8 | 0.1% | Jun 26, 2026 | Notepad++ is a free and open-source source code editor. From 8.9.4 until 8.9.6, Notepad++ contains a local privilege esc... |
| CVE-2026-46604 | HIGH | 7.5 | 0.3% | Jun 26, 2026 | The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. |
| CVE-2026-38641 | HIGH | 7.5 | 0.2% | Jun 26, 2026 | An issue in the DSO::mmap_and_copy function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) ... |
| CVE-2026-38639 | HIGH | 7.5 | 0.2% | Jun 26, 2026 | An issue in the parse_month function (/time/strptime.rs) of relibc commit ab6a2e allows attackers to cause a Denial of S... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now