2026 CVE Vulnerabilities
48,099 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57456 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/pytho... |
| CVE-2026-57455 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in ... |
| CVE-2026-57453 | HIGH | 7.3 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. From 9.1.1784 until 9.2.0678, when the bundled zip plugin autoload/zip.... |
| CVE-2026-55895 | HIGH | 7.8 | 0.2% | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s... |
| CVE-2026-55693 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0653, the tree_count_words() function in src/spellfile.c f... |
| CVE-2026-55477 | HIGH | 7.2 | 0.3% | Jun 25, 2026 | 3X-UI is a web control panel for managing Xray-core servers. Prior to 3.3.1, an authenticated administrator can abuse th... |
| CVE-2026-54036 | HIGH | 8.1 | 0.2% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the GET /api/auth/2fa/en... |
| CVE-2026-12844 | HIGH | 7.5 | 0.4% | Jun 25, 2026 | List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow in the pairwise function. pairwise() coll... |
| CVE-2026-57532 | HIGH | 8.8 | 0.3% | Jun 25, 2026 | Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF ... |
| CVE-2026-57435 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri’s CRuby nat... |
| CVE-2026-57434 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri contains a ... |
| CVE-2026-57236 | HIGH | 8.2 | 0.3% | Jun 25, 2026 | Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, calling Document#enc... |
| CVE-2026-57235 | HIGH | 8.2 | 0.3% | Jun 25, 2026 | Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::NodeS... |
| CVE-2026-46735 | HIGH | 7.8 | 0.7% | Jun 25, 2026 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Neutralization of Special Ele... |
| CVE-2026-56122 | HIGH | 8.7 | 0.4% | Jun 25, 2026 | Winstone Servlet Engine through 0.9.10 contains a path traversal vulnerability that allows unauthenticated attackers to ... |
| CVE-2026-56071 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.53.1 versions. |
| CVE-2026-56054 | HIGH | 7.7 | 0.4% | Jun 25, 2026 | Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions. |
| CVE-2026-56053 | HIGH | 8.8 | 0.4% | Jun 25, 2026 | Subscriber PHP Object Injection in EventPrime <= 4.3.4.1 versions. |
| CVE-2026-56051 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions. |
| CVE-2026-56049 | HIGH | 8.5 | 0.4% | Jun 25, 2026 | Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions. |
| CVE-2026-56042 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | Customer Cross Site Scripting (XSS) in Advanced Order Export For WooCommerce <= 4.0.9 versions. |
| CVE-2026-56014 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | Unauthenticated Cross Site Scripting (XSS) in Master Slider <= 3.11.2 versions. |
| CVE-2026-56006 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | Unauthenticated Cross Site Scripting (XSS) in H5P <= 1.17.6 versions. |
| CVE-2026-56005 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions. |
| CVE-2026-54848 | HIGH | 8.3 | 0.2% | Jun 25, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows R... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now