2026 CVE Vulnerabilities
47,686 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48587 | MEDIUM | 5.3 | 0.4% | Jun 3, 2026 | An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Djan... |
| CVE-2026-47325 | MEDIUM | 6.9 | 0.2% | Jun 3, 2026 | ProjectsAndPrograms school-management-system uses predictable credentials by generating student's and teacher's password... |
| CVE-2026-47324 | MEDIUM | 5.1 | 0.3% | Jun 3, 2026 | ProjectsAndPrograms school-management-system is vulnerable to Stored Cross‑Site Scripting (XSS) in multiple attributes o... |
| CVE-2026-44546 | MEDIUM | 5.3 | 0.2% | Jun 3, 2026 | daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket... |
| CVE-2026-10722 | MEDIUM | 5.5 | 0.2% | Jun 3, 2026 | A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go... |
| CVE-2026-5078 | MEDIUM | 5.3 | 0.2% | Jun 3, 2026 | Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization reque... |
| CVE-2026-10703 | MEDIUM | 6.3 | 0.2% | Jun 3, 2026 | A security vulnerability has been detected in EIPStackGroup OpENer up to 2.3.0. Affected is the function CreateMessageRo... |
| CVE-2026-10693 | MEDIUM | 6.3 | 0.2% | Jun 3, 2026 | A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Affected by this vulner... |
| CVE-2026-9732 | MEDIUM | 4.3 | 0.1% | Jun 3, 2026 | The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forger... |
| CVE-2026-7421 | MEDIUM | 4.4 | 0.2% | Jun 3, 2026 | The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and inclu... |
| CVE-2026-10692 | MEDIUM | 4.3 | 0.3% | Jun 3, 2026 | A weakness has been identified in johnhuang316 code-index-mcp up to 2.14.0. Affected is the function is_safe_regex_patte... |
| CVE-2026-10691 | MEDIUM | 4.3 | 0.4% | Jun 3, 2026 | A security flaw has been discovered in wonderwhy-er DesktopCommanderMCP up to 0.2.38. This impacts an unknown function o... |
| CVE-2026-10690 | MEDIUM | 6.3 | 0.2% | Jun 3, 2026 | A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of ... |
| CVE-2026-44653 | MEDIUM | 6.5 | 0.3% | Jun 2, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, users... |
| CVE-2026-42507 | MEDIUM | 5.3 | 0.4% | Jun 2, 2026 | When returning errors, functions in the net/textproto package would include its input as part of the error. This might a... |
| CVE-2026-41412 | MEDIUM | 4.9 | 0.3% | Jun 2, 2026 | alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to versio... |
| CVE-2026-27145 | MEDIUM | 6.5 | 0.6% | Jun 2, 2026 | (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN... |
| CVE-2026-10718 | MEDIUM | 4.6 | 0.1% | Jun 2, 2026 | Out of bounds write in openSeaChest’s Trim/Unmap operation in Seagate’s openSeaChest v26.03.0 on all supported platforms... |
| CVE-2026-10688 | MEDIUM | 5.5 | 0.2% | Jun 2, 2026 | A vulnerability was determined in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. The impacted elem... |
| CVE-2026-10662 | MEDIUM | 6.3 | 0.2% | Jun 2, 2026 | A vulnerability was found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. The affected element i... |
| CVE-2026-35212 | MEDIUM | 6.1 | 0.1% | Jun 2, 2026 | OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Versions prior to 7... |
| CVE-2026-10661 | MEDIUM | 4.3 | 0.2% | Jun 2, 2026 | A vulnerability has been found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. Impacted is the f... |
| CVE-2026-10650 | MEDIUM | 5.5 | 0.4% | Jun 2, 2026 | A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of t... |
| CVE-2026-45289 | MEDIUM | 5.3 | 0.1% | Jun 2, 2026 | CloudburstMC Protocol is a protocol library for Minecraft Bedrock Edition. Prior to version 3.0.0.Beta12-20260420.182526... |
| CVE-2026-41569 | MEDIUM | 6.1 | 0.2% | Jun 2, 2026 | authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now