2026 CVE Vulnerabilities
47,686 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10624 | MEDIUM | 4.3 | 0.2% | Jun 2, 2026 | A vulnerability has been found in SourceCodester Human Resource Management 1.0. Affected by this vulnerability is an unk... |
| CVE-2026-8035 | MEDIUM | 5.5 | 0.1% | Jun 2, 2026 | Improper input validation in the NI-PAL kernel driver may allow a local authenticated user to cause a denial of service ... |
| CVE-2026-5074 | MEDIUM | 6.5 | 0.3% | Jun 2, 2026 | The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'sSortDir_0' parameter of the `get_priv... |
| CVE-2026-48682 | MEDIUM | 5.9 | 0.3% | Jun 2, 2026 | FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet parser. In src/simple_packe... |
| CVE-2026-48597 | MEDIUM | 5.9 | 0.3% | Jun 2, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via at... |
| CVE-2026-48595 | MEDIUM | 5.9 | 0.5% | Jun 2, 2026 | Improper Handling of Case Sensitivity vulnerability in elixir-tesla tesla allows credential leakage to a third-party ori... |
| CVE-2026-40181 | MEDIUM | 6.1 | 0.2% | Jun 2, 2026 | React Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to th... |
| CVE-2026-35049 | MEDIUM | 6.5 | 0.2% | Jun 2, 2026 | wire-ios is an iOS client for the Wire secure messaging application. Prior to version 4.16.0, upon receiving a crafted m... |
| CVE-2026-33553 | MEDIUM | 6.1 | 0.2% | Jun 2, 2026 | Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS. |
| CVE-2026-33245 | MEDIUM | 4.7 | 0.2% | Jun 2, 2026 | React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Co... |
| CVE-2026-30586 | MEDIUM | 6.1 | 0.2% | Jun 2, 2026 | Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote attacker to obtain sensitive information v... |
| CVE-2026-10702 | MEDIUM | 4.3 | 0.6% | Jun 2, 2026 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3. |
| CVE-2026-10616 | MEDIUM | 4.3 | 0.2% | Jun 2, 2026 | A weakness has been identified in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function TeamTasksTo... |
| CVE-2026-49943 | MEDIUM | 6.3 | 0.3% | Jun 2, 2026 | CZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buffer overflow in the BGP AS_PATH mask matchi... |
| CVE-2026-42073 | MEDIUM | 6.5 | 0.2% | Jun 2, 2026 | OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0... |
| CVE-2026-40713 | MEDIUM | 6.1 | 0.2% | Jun 2, 2026 | Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access control vulnerability. An unauthenti... |
| CVE-2026-40571 | MEDIUM | 5.3 | 0.2% | Jun 2, 2026 | NamelessMC is website software for Minecraft servers. In version 2.2.4, `core/classes/Misc/ProfilePostReactionContext.ph... |
| CVE-2026-40314 | MEDIUM | 6.9 | 0.3% | Jun 2, 2026 | NamelessMC is website software for Minecraft servers. In version 2.2.4,`core/classes/Misc/ProfilePostReactionContext.php... |
| CVE-2026-35447 | MEDIUM | 5.3 | 0.2% | Jun 2, 2026 | NamelessMC is website software for Minecraft servers. In version 2.2.4, the profile page (modules/Core/pages/profile.php... |
| CVE-2026-35443 | MEDIUM | 5.3 | 0.2% | Jun 2, 2026 | NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/classes/ForumPostReactionContext.... |
| CVE-2026-33244 | MEDIUM | 5.4 | 0.1% | Jun 2, 2026 | React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabl... |
| CVE-2026-1871 | MEDIUM | 6.5 | 0.3% | Jun 2, 2026 | TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validat... |
| CVE-2026-9590 | MEDIUM | 5.3 | 0.2% | Jun 2, 2026 | Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an aut... |
| CVE-2026-9522 | MEDIUM | 5.4 | 0.1% | Jun 2, 2026 | Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authe... |
| CVE-2026-7299 | MEDIUM | 5.4 | 0.3% | Jun 2, 2026 | Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them i... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now