2026 CVE Vulnerabilities
47,701 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-1871 | MEDIUM | 6.5 | 0.3% | Jun 2, 2026 | TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validat... |
| CVE-2026-9590 | MEDIUM | 5.3 | 0.2% | Jun 2, 2026 | Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an aut... |
| CVE-2026-9522 | MEDIUM | 5.4 | 0.1% | Jun 2, 2026 | Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authe... |
| CVE-2026-7299 | MEDIUM | 5.4 | 0.3% | Jun 2, 2026 | Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them i... |
| CVE-2026-49753 | MEDIUM | 6.3 | 0.3% | Jun 2, 2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint Mint allow... |
| CVE-2026-45684 | MEDIUM | 5.3 | 0.2% | Jun 2, 2026 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0... |
| CVE-2026-45682 | MEDIUM | 5.5 | 0.2% | Jun 2, 2026 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0... |
| CVE-2026-45681 | MEDIUM | 5.9 | 0.3% | Jun 2, 2026 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0... |
| CVE-2026-45679 | MEDIUM | 6.5 | 0.2% | Jun 2, 2026 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0... |
| CVE-2026-45676 | MEDIUM | 5.5 | 0.2% | Jun 2, 2026 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0... |
| CVE-2026-45554 | MEDIUM | 5.3 | 0.3% | Jun 2, 2026 | NiceGUI is a Python-based UI framework. Prior to version 3.12.0, two FastAPI routes that serve per-component static asse... |
| CVE-2026-45080 | MEDIUM | 6.9 | 0.2% | Jun 2, 2026 | Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, improper access co... |
| CVE-2026-38978 | MEDIUM | 5.3 | 0.3% | Jun 2, 2026 | transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths. |
| CVE-2026-35718 | MEDIUM | 6.5 | 0.7% | Jun 2, 2026 | A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allow... |
| CVE-2026-35716 | MEDIUM | 6.3 | 0.3% | Jun 2, 2026 | A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authe... |
| CVE-2026-34460 | MEDIUM | 5.4 | 0.1% | Jun 2, 2026 | NamelessMC is website software for Minecraft servers. In versions 2.2.4 and prior, the OAuth callback handling does not ... |
| CVE-2026-7313 | MEDIUM | 4.9 | 0.3% | Jun 2, 2026 | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 ... |
| CVE-2026-49782 | MEDIUM | 5.4 | 0.1% | Jun 2, 2026 | Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Acce... |
| CVE-2026-43965 | MEDIUM | 5.6 | 0.2% | Jun 2, 2026 | Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/pa... |
| CVE-2026-42795 | MEDIUM | 5.1 | 0.1% | Jun 2, 2026 | Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in th... |
| CVE-2026-41918 | MEDIUM | 5.9 | 0.2% | Jun 2, 2026 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applicatio... |
| CVE-2026-35717 | MEDIUM | 6.3 | 0.3% | Jun 2, 2026 | A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows auth... |
| CVE-2026-32685 | MEDIUM | 4.6 | 0.2% | Jun 2, 2026 | Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file read and file write... |
| CVE-2026-32250 | MEDIUM | 4.3 | 0.2% | Jun 2, 2026 | NamelessMC is website software for Minecraft servers. A Reflected Cross-Site Scripting (XSS) vulnerability was discovere... |
| CVE-2026-28116 | MEDIUM | 5.9 | 0.1% | Jun 2, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emilia Projects Pr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now