2026 CVE Vulnerabilities
48,075 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-38640 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows attackers to cause a De... |
| CVE-2026-38637 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of S... |
| CVE-2026-37452 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensit... |
| CVE-2026-12473 | HIGH | 8.3 | 0.2% | Jun 25, 2026 | Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter wit... |
| CVE-2026-57520 | HIGH | 7.1 | 0.4% | Jun 25, 2026 | Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users wi... |
| CVE-2026-55960 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypassing chain validation. A raw pub... |
| CVE-2026-55958 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In tsip_StoreMessage() the capacity check guarding th... |
| CVE-2026-46602 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image cont... |
| CVE-2026-46601 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size. |
| CVE-2026-37454 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensit... |
| CVE-2026-37453 | HIGH | 7.5 | 0.4% | Jun 25, 2026 | Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensit... |
| CVE-2026-37149 | HIGH | 7.7 | 0.2% | Jun 25, 2026 | GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was discovered to contain a SQL injection vulnerabil... |
| CVE-2026-12340 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | Out-of-bounds heap read during SM2/SM3 certificate signature verification. When parsing a certificate with an SM3wSM2 si... |
| CVE-2026-11310 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | X.509 trust-chain bypass in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects on... |
| CVE-2026-10512 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | The X25519 x86_64 assembly implementation fails to clear the most significant bit during the final modular reduction, so... |
| CVE-2026-10097 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | wolfSSL's AVX2-optimized ML-KEM implementation (mlkem_cmp_avx2) compares only 1536 of the 1568 ciphertext bytes during t... |
| CVE-2026-56790 | HIGH | 7.3 | 0.2% | Jun 25, 2026 | CANBoat through 6.22, fixed in commit a5a22b7, contains an off-by-one global buffer overflow in the searchForPgn() funct... |
| CVE-2026-56789 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | RTKLIB through 2.4.3 contains a heap buffer overflow vulnerability in the readrnxobsb function in src/rinex.c that allow... |
| CVE-2026-56788 | HIGH | 7.1 | 0.1% | Jun 25, 2026 | RTKLIB through 2.4.3 contains an out-of-bounds read vulnerability in getcodepri function when processing unrecognized RI... |
| CVE-2026-56787 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | RTKLIB through 2.4.3 contains an off-by-one out-of-bounds read vulnerability in the decode_ssr3 function at src/rtcm3.c:... |
| CVE-2026-56771 | HIGH | 8.5 | 0.2% | Jun 25, 2026 | NewsBlur before version 14.5.0 contains a server-side request forgery vulnerability in the add_url endpoint that allows ... |
| CVE-2026-56770 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | libais through 0.15 VdmStream::AddLine uses an unchecked sentinel value as a vector index when processing AIS sentences ... |
| CVE-2026-56769 | HIGH | 8.5 | 0.2% | Jun 25, 2026 | Huly Platform through 0.7.423, fixed in commit 68cbf8a contains an authenticated server-side request forgery vulnerabili... |
| CVE-2026-56768 | HIGH | 8.8 | 0.4% | Jun 25, 2026 | Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthe... |
| CVE-2026-56767 | HIGH | 8.8 | 0.3% | Jun 25, 2026 | Maxun before 0.0.42 contains a cross-tenant insecure direct object reference vulnerability in storage and webhook API ha... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now