2026 CVE Vulnerabilities
48,064 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48933 | HIGH | 7.5 | 3.7% | Jun 26, 2026 | A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2Gi... |
| CVE-2026-48619 | HIGH | 7.5 | 0.5% | Jun 26, 2026 | A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out... |
| CVE-2026-48615 | HIGH | 7.5 | 0.4% | Jun 26, 2026 | A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. Wh... |
| CVE-2026-9221 | HIGH | 8.7 | 0.2% | Jun 26, 2026 | The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request si... |
| CVE-2026-9220 | HIGH | 8.7 | 0.2% | Jun 26, 2026 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and i... |
| CVE-2026-9219 | HIGH | 8.3 | 0.2% | Jun 26, 2026 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derive... |
| CVE-2026-40083 | HIGH | 7.2 | 0.3% | Jun 25, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have SQL Injection through... |
| CVE-2026-8720 | HIGH | 7.5 | 0.1% | Jun 25, 2026 | wc_Blake2bHmacFinal and wc_Blake2sHmacFinal discard the message when the key length exceeds the block size, producing a ... |
| CVE-2026-7532 | HIGH | 7.5 | 0.1% | Jun 25, 2026 | iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constraints are not enforced ... |
| CVE-2026-7511 | HIGH | 7.5 | 0.1% | Jun 25, 2026 | PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bo... |
| CVE-2026-6331 | HIGH | 7.5 | 0.1% | Jun 25, 2026 | HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as valid during HMAC ve... |
| CVE-2026-6325 | HIGH | 7.5 | 0.1% | Jun 25, 2026 | Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list, allowing a write pas... |
| CVE-2026-54479 | HIGH | 7.3 | 0.2% | Jun 25, 2026 | The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to ... |
| CVE-2026-50176 | HIGH | 8.7 | 0.4% | Jun 25, 2026 | The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absenc... |
| CVE-2026-22879 | HIGH | 8.1 | 0.3% | Jun 25, 2026 | vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability |
| CVE-2026-13283 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a... |
| CVE-2026-13281 | HIGH | 8.3 | 0.2% | Jun 25, 2026 | Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the rend... |
| CVE-2026-12992 | HIGH | 7.4 | 0.2% | Jun 25, 2026 | A flaw was found in Apicurio Registry. The WSDLReaderAccessor creates a wsdl4j WSDLReader without disabling the javax.ws... |
| CVE-2026-12975 | HIGH | 8.5 | 0.2% | Jun 25, 2026 | A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without ena... |
| CVE-2026-11800 | HIGH | 8.1 | 0.2% | Jun 25, 2026 | A flaw was found in Keycloak. This JWT algorithm confusion vulnerability in the JWT Authorization Grant flow allows an a... |
| CVE-2026-11703 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | Missing SNI/ALPN binding on stateful (session-ID) resumption, which previously skipped the binding check performed for t... |
| CVE-2026-6731 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN... |
| CVE-2026-6679 | HIGH | 7.5 | 0.4% | Jun 25, 2026 | A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. T... |
| CVE-2026-38640 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows attackers to cause a De... |
| CVE-2026-38637 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of S... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now