2026 CVE Vulnerabilities
47,636 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47306 | MEDIUM | 6.1 | 0.1% | Jun 4, 2026 | Uncontrolled Recursion vulnerability in Samsung Open Source rlottie allows Oversized Serialized Data Payloads. This iss... |
| CVE-2026-10305 | MEDIUM | 6.1 | 0.1% | Jun 4, 2026 | Out-of-bounds read vulnerability in Samsung Open Source rlottie allows Overread Buffers. This issue affects rlottie: be... |
| CVE-2026-50212 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user... |
| CVE-2026-50206 | MEDIUM | 6.8 | 0.7% | Jun 4, 2026 | Incoming VPN network profile settings fail to process special characters safely, enabling command injection via maliciou... |
| CVE-2026-49204 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation. |
| CVE-2026-49192 | MEDIUM | 5.4 | 0.1% | Jun 4, 2026 | The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware seri... |
| CVE-2026-50219 | MEDIUM | 5.9 | 0.2% | Jun 4, 2026 | libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_GetBuffer, XML_Parse, XML_ParseBuffer, XML_Pars... |
| CVE-2026-10805 | MEDIUM | 6.7 | 0.1% | Jun 4, 2026 | A flaw was found in NetworkManager. This local privilege escalation vulnerability exists in NetworkManager's dhclient ba... |
| CVE-2026-44917 | MEDIUM | 4.9 | 0.3% | Jun 4, 2026 | OpenStack Ironic before 35.0.2 allows a malicious authenticated project admin or manager to read local files on the Iron... |
| CVE-2026-10597 | MEDIUM | 6.9 | 0.2% | Jun 4, 2026 | OMICARD EDM developed by ITPison has a Insecure Direct Object Reference vulnerability, allowing unauthenticated remote a... |
| CVE-2026-8653 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in ... |
| CVE-2026-7764 | MEDIUM | 6.8 | 0.1% | Jun 4, 2026 | An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versio... |
| CVE-2026-8722 | MEDIUM | 6.5 | 0.2% | Jun 4, 2026 | Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked fo... |
| CVE-2026-10775 | MEDIUM | 5.3 | 0.1% | Jun 3, 2026 | A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_h... |
| CVE-2026-43924 | MEDIUM | 4.8 | 0.3% | Jun 3, 2026 | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Redirect module doe... |
| CVE-2026-40495 | MEDIUM | 6.9 | 0.3% | Jun 3, 2026 | FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 leak the exact system v... |
| CVE-2026-37700 | MEDIUM | 4.1 | 0.2% | Jun 3, 2026 | Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via t... |
| CVE-2026-26825 | MEDIUM | 5.3 | 0.2% | Jun 3, 2026 | A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reacha... |
| CVE-2026-26824 | MEDIUM | 6.5 | 0.2% | Jun 3, 2026 | libxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the OLE container parser. Memory al... |
| CVE-2026-45702 | MEDIUM | 5.5 | 0.2% | Jun 3, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-45614 | MEDIUM | 4.7 | 0.1% | Jun 3, 2026 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte... |
| CVE-2026-42840 | MEDIUM | 5.1 | 0.2% | Jun 3, 2026 | An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and... |
| CVE-2026-42839 | MEDIUM | 4.8 | 0.3% | Jun 3, 2026 | An authenticated ERPNext user with Item record edit permissions can persist arbitrary HTML/JavaScript in the item_name, ... |
| CVE-2026-26379 | MEDIUM | 6.5 | 0.2% | Jun 3, 2026 | Koha versions up to 25.11 contain a Server-Side Request Forgery (SSRF) vulnerability via the Z39.50/SRU server configura... |
| CVE-2026-26378 | MEDIUM | 5.4 | 0.3% | Jun 3, 2026 | Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now