2026 CVE Vulnerabilities
47,574 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10808 | MEDIUM | 6.3 | 0.2% | Jun 4, 2026 | A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown function of the file ... |
| CVE-2026-10807 | MEDIUM | 6.3 | 0.2% | Jun 4, 2026 | A vulnerability was determined in mjperpinosa stumasy. The impacted element is an unknown function of the file applicati... |
| CVE-2026-10806 | MEDIUM | 6.3 | 0.2% | Jun 4, 2026 | A vulnerability was found in mjperpinosa stumasy. The affected element is an unknown function of the file application/PH... |
| CVE-2026-10804 | MEDIUM | 4.7 | 0.1% | Jun 4, 2026 | A vulnerability has been found in Streamlit up to 1.53.0. Impacted is an unknown function in the library lib/streamlit/r... |
| CVE-2026-10802 | MEDIUM | 4.3 | 0.3% | Jun 4, 2026 | A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unknown code in the libra... |
| CVE-2026-49077 | MEDIUM | 5.3 | 0.2% | Jun 4, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMembe... |
| CVE-2026-8916 | MEDIUM | 6.1 | 0.1% | Jun 4, 2026 | Out-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rlottie: b... |
| CVE-2026-50226 | MEDIUM | 5.3 | 0.2% | Jun 4, 2026 | Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrar... |
| CVE-2026-50224 | MEDIUM | 4.9 | 0.2% | Jun 4, 2026 | The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall l... |
| CVE-2026-4881 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being... |
| CVE-2026-49510 | MEDIUM | 6.1 | 0.1% | Jun 4, 2026 | Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Integer Attacks. This issue affects ... |
| CVE-2026-47320 | MEDIUM | 6.1 | 0.1% | Jun 4, 2026 | Access of uninitialized pointer, Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Pointer Mani... |
| CVE-2026-47319 | MEDIUM | 6.1 | 0.1% | Jun 4, 2026 | Memory allocation with excessive size value vulnerability in Samsung Open Source rlottie allows Excessive Allocation. T... |
| CVE-2026-47318 | MEDIUM | 6.1 | 0.1% | Jun 4, 2026 | Stack-based buffer overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects rl... |
| CVE-2026-47306 | MEDIUM | 6.1 | 0.1% | Jun 4, 2026 | Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads. This iss... |
| CVE-2026-10305 | MEDIUM | 6.1 | 0.1% | Jun 4, 2026 | Out-of-bounds read vulnerability in Samsung Open Source rlottie allows Overread Buffers. This issue affects rlottie: be... |
| CVE-2026-50212 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user... |
| CVE-2026-50206 | MEDIUM | 6.8 | 0.7% | Jun 4, 2026 | Incoming VPN network profile settings fail to process special characters safely, enabling command injection via maliciou... |
| CVE-2026-49204 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation. |
| CVE-2026-49192 | MEDIUM | 5.4 | 0.1% | Jun 4, 2026 | The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware seri... |
| CVE-2026-50219 | MEDIUM | 5.9 | 0.2% | Jun 4, 2026 | libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_Pars... |
| CVE-2026-10805 | MEDIUM | 6.7 | 0.1% | Jun 4, 2026 | A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient ba... |
| CVE-2026-44917 | MEDIUM | 4.9 | 0.3% | Jun 4, 2026 | OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Iron... |
| CVE-2026-10597 | MEDIUM | 6.9 | 0.2% | Jun 4, 2026 | OMICARD EDM developed by ITPison has a Insecure Direct Object Reference vulnerability, allowing unauthenticated remote a... |
| CVE-2026-8653 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now