2026 CVE Vulnerabilities
48,099 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54845 | HIGH | 8.1 | 0.3% | Jun 25, 2026 | Unauthenticated Local File Inclusion in MDTF <= 1.3.8 versions. |
| CVE-2026-54844 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions. |
| CVE-2026-54842 | HIGH | 8.1 | 0.2% | Jun 25, 2026 | Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control S... |
| CVE-2026-54841 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions. |
| CVE-2026-54838 | HIGH | 8.5 | 0.3% | Jun 25, 2026 | Subscriber SQL Injection in WC Vendors Marketplace <= 2.6.8 versions. |
| CVE-2026-54830 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions. |
| CVE-2026-54829 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt... |
| CVE-2026-54828 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | Unauthenticated Broken Access Control in Motors <= 1.4.109 versions. |
| CVE-2026-54822 | HIGH | 8.5 | 0.3% | Jun 25, 2026 | Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions. |
| CVE-2026-54821 | HIGH | 7.4 | 0.3% | Jun 25, 2026 | Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions. |
| CVE-2026-49506 | HIGH | 7.2 | 0.5% | Jun 25, 2026 | Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted ... |
| CVE-2026-47151 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed ClearWeekdaySchedule messages can trigger out-of-bounds writes into Door Lock... |
| CVE-2026-47150 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed IAS Zone enrollment messages can trigger an out-of-bounds state-table write a... |
| CVE-2026-47147 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | In EmberZNet v9.0.2 and earlier, malformed OTA requests can drive the OTA server parser into out-of-bounds reads. A limi... |
| CVE-2026-46734 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain an Improper Certificate Validation vulner... |
| CVE-2026-46733 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3, contain an Improper Access Control vulnerabil... |
| CVE-2026-46732 | HIGH | 7 | 0.1% | Jun 25, 2026 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contain a Concurrent Execution using Shared Resou... |
| CVE-2026-2815 | HIGH | 8.4 | 0.2% | Jun 25, 2026 | Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys |
| CVE-2026-27366 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions. |
| CVE-2026-33612 | HIGH | 7.5 | 0.1% | Jun 25, 2026 | A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning. |
| CVE-2026-56091 | HIGH | 8.2 | 0.4% | Jun 25, 2026 | When using Apache Shiro with the shiro-guice module in a web servlet context, a specially crafted HTTP request may cause... |
| CVE-2026-53277 | HIGH | 8.8 | 0.1% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Take the SRCU lock for page table walks... |
| CVE-2026-53276 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix a use-after-free of the hci_con... |
| CVE-2026-53275 | HIGH | 8.8 | 0.3% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: mcast: Fix use-after-free when processing MLD... |
| CVE-2026-53273 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: tee: optee: prevent use-after-free when the client ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now