2026 CVE Vulnerabilities
48,064 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54826 | HIGH | 7.6 | 0.3% | Jun 26, 2026 | Subscriber Insecure Direct Object References (IDOR) in SupportCandy <= 3.4.6 versions. |
| CVE-2026-54824 | HIGH | 7.5 | — | Jun 26, 2026 | Unauthenticated Sensitive Data Exposure in Ads by WPQuads <= 3.0.3 versions. |
| CVE-2026-45257 | HIGH | 7.8 | — | Jun 26, 2026 | The KTLS receive path decrypted each record in place, assuming that the mbufs holding received data were anonymous and s... |
| CVE-2026-30041 | HIGH | 7.5 | — | Jun 26, 2026 | An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code... |
| CVE-2026-57923 | HIGH | 7.5 | 0.2% | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying pr... |
| CVE-2026-57921 | HIGH | 7.5 | 0.2% | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment te... |
| CVE-2026-57920 | HIGH | 7.7 | 0.2% | Jun 26, 2026 | Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certai... |
| CVE-2026-57915 | HIGH | 7.3 | 0.3% | Jun 26, 2026 | It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized... |
| CVE-2026-40711 | HIGH | 8 | — | Jun 26, 2026 | Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-po... |
| CVE-2026-57918 | HIGH | 7.1 | — | Jun 26, 2026 | libnfs through 6.0.2 before 935b8db has an xid integer underflow in READ_IOVEC in rpc_read_from_socket in lib/socket.c d... |
| CVE-2026-57913 | HIGH | 7.5 | — | Jun 26, 2026 | Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transc... |
| CVE-2026-57912 | HIGH | 7.5 | — | Jun 26, 2026 | Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited students, and notes e... |
| CVE-2026-11702 | HIGH | 7.5 | 0.3% | Jun 26, 2026 | Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes. When an objec... |
| CVE-2026-11625 | HIGH | 7.5 | 0.3% | Jun 26, 2026 | Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. When an object is in... |
| CVE-2026-57877 | HIGH | 8.6 | 0.2% | Jun 26, 2026 | An unauthenticated format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier.... |
| CVE-2026-57876 | HIGH | 7.5 | 0.3% | Jun 26, 2026 | An unauthenticated out-of-bounds write vulnerability exists in onvif.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 an... |
| CVE-2026-57875 | HIGH | 7.5 | 1.3% | Jun 26, 2026 | An unauthenticated NULL pointer dereference vulnerability exists in the HTTP request parsing logic of multiple CGI compo... |
| CVE-2026-57874 | HIGH | 7.5 | 0.3% | Jun 26, 2026 | An unauthenticated buffer overflow vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V... |
| CVE-2026-57873 | HIGH | 7.5 | 0.2% | Jun 26, 2026 | An unauthenticated NULL pointer dereference vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-... |
| CVE-2026-57872 | HIGH | 7.5 | 1.0% | Jun 26, 2026 | An unauthenticated directory traversal vulnerability exists in get_fcont.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.1... |
| CVE-2026-49486 | HIGH | 7.5 | 0.1% | Jun 26, 2026 | The Apache Airflow FTP provider's `FTPSHook.get_conn()` created an `ftplib.FTP_TLS` connection but never called `prot_p(... |
| CVE-2026-10835 | HIGH | 7.7 | 0.2% | Jun 26, 2026 | The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter passed to one ... |
| CVE-2026-10823 | HIGH | 7.5 | 0.1% | Jun 26, 2026 | The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST API endpoints and do... |
| CVE-2026-8797 | HIGH | 8.5 | 0.1% | Jun 26, 2026 | An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access t... |
| CVE-2026-50741 | HIGH | 8.8 | 0.3% | Jun 26, 2026 | Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now