2026 CVE Vulnerabilities
47,534 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-50233 | MEDIUM | 6.9 | 0.3% | Jun 5, 2026 | Lyrion Music Server 9.2.0 contains an arbitrary directory listing vulnerability in its readdirectory query, exposed thro... |
| CVE-2026-50230 | MEDIUM | 6.1 | 0.3% | Jun 5, 2026 | Lyrion Music Server 9.2.0 contains an unauthenticated reflected cross-site scripting vulnerability in the server.log end... |
| CVE-2026-50263 | MEDIUM | 5.5 | 0.1% | Jun 5, 2026 | A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-af... |
| CVE-2026-50262 | MEDIUM | 5.5 | 0.1% | Jun 5, 2026 | An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong... |
| CVE-2026-25659 | MEDIUM | 6.5 | 0.2% | Jun 5, 2026 | Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulne... |
| CVE-2026-25658 | MEDIUM | 6.5 | 0.2% | Jun 5, 2026 | Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulne... |
| CVE-2026-25657 | MEDIUM | 6.5 | 0.2% | Jun 5, 2026 | Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structur... |
| CVE-2026-11346 | MEDIUM | 5.3 | 0.2% | Jun 5, 2026 | A Server-Side Request Forgery (SSRF) vulnerability in the custom process creation feature of linqi allows an authenticat... |
| CVE-2026-11345 | MEDIUM | 6.9 | 0.4% | Jun 5, 2026 | An Improper Authentication vulnerability in the /api/Cdn/GetFile endpoint of linqi allows unauthenticated, remote attack... |
| CVE-2026-21038 | MEDIUM | 5.5 | 0.1% | Jun 5, 2026 | Improper input validation in Samsung Android USB Driver for Windows prior to version 1.9.5.0 allows local attacker to ac... |
| CVE-2026-21036 | MEDIUM | 5.5 | 0.1% | Jun 5, 2026 | Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive informa... |
| CVE-2026-21028 | MEDIUM | 5.5 | 0.1% | Jun 5, 2026 | Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive in... |
| CVE-2026-21026 | MEDIUM | 5.5 | 0.1% | Jun 5, 2026 | Improper export of android application components in SpriteWallpaper prior to SMR Jun-2026 Release 1 allows local attack... |
| CVE-2026-21025 | MEDIUM | 5.5 | 0.1% | Jun 5, 2026 | Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive i... |
| CVE-2026-21017 | MEDIUM | 5.5 | 0.1% | Jun 5, 2026 | Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attack... |
| CVE-2026-21826 | MEDIUM | 6.1 | 0.1% | Jun 5, 2026 | HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection. An attacker ca... |
| CVE-2026-21825 | MEDIUM | 6.1 | 0.2% | Jun 5, 2026 | HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center.... |
| CVE-2026-10732 | MEDIUM | 6.4 | 0.5% | Jun 5, 2026 | All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when ext... |
| CVE-2026-50592 | MEDIUM | 6.4 | 0.1% | Jun 5, 2026 | In Znuny LTS before 6.5.21 and Znuny before 7.3.3, there is reflected XSS in AdminCommunicationLog (aka the communicat... |
| CVE-2026-50591 | MEDIUM | 5.4 | 0.1% | Jun 5, 2026 | In Znuny LTS before 6.5.21 and Znuny before 7.3.3, XSS can occur via stored user preferences. |
| CVE-2026-50590 | MEDIUM | 4.5 | 0.1% | Jun 5, 2026 | In Mimecast Incydr before 2.6.0, arbitrary file access can occur. |
| CVE-2026-11326 | MEDIUM | 6 | 0.2% | Jun 5, 2026 | OpenAI Atlas before 1.2025.288.15 exposed privileged browser APIs to web content on *.openai.com origins. A cross-site s... |
| CVE-2026-11309 | MEDIUM | 4.3 | 0.1% | Jun 5, 2026 | Insufficient policy enforcement in History in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform ... |
| CVE-2026-11308 | MEDIUM | 6.3 | 0.1% | Jun 5, 2026 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a u... |
| CVE-2026-11302 | MEDIUM | 4.3 | 0.2% | Jun 5, 2026 | Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attack... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now