2026 CVE Vulnerabilities
48,182 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47110 | HIGH | 7.1 | 0.3% | Jun 24, 2026 | Tiptap for PHP before version 2.1.1 contains an input validation vulnerability that allows authenticated attackers to ca... |
| CVE-2026-2050 | HIGH | 7.8 | 0.6% | Jun 24, 2026 | GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a... |
| CVE-2026-10043 | HIGH | 7.8 | 0.3% | Jun 24, 2026 | MosaicML Composer Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remot... |
| CVE-2026-7539 | HIGH | 7.3 | 0.1% | Jun 24, 2026 | A potential security vulnerability has been identified in the HP Accessory WMI Provider installer for some HP Docking St... |
| CVE-2026-52812 | HIGH | 7.1 | 0.2% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git LFS storage is content-addressed by OID alone (<LFS... |
| CVE-2026-52810 | HIGH | 7.1 | 0.4% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git smart HTTP authorizes POST …/git-receive-pack using... |
| CVE-2026-52808 | HIGH | 7.1 | 0.5% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, three API endpoints — PATCH /api/v1/repos/:owner/:repo/... |
| CVE-2026-52805 | HIGH | 8.7 | 0.4% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, a Server-Side Request Forgery (SSRF) vulnerability exis... |
| CVE-2026-52801 | HIGH | 8.1 | 0.6% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, the Gogs Mirror Settings functionality provide an alter... |
| CVE-2026-52800 | HIGH | 8.8 | 0.2% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization team member management can be performed vi... |
| CVE-2026-52799 | HIGH | 7.5 | 0.4% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file ... |
| CVE-2026-52798 | HIGH | 8.9 | 0.4% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, although .ipynb previews are sanitized on the server si... |
| CVE-2026-52797 | HIGH | 8.5 | 0.4% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.0, as an authorized user, an intruder can dictate the valu... |
| CVE-2026-50129 | HIGH | 7.5 | 0.3% | Jun 24, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.11, 4.4.18, and 4.3.24, a DoS c... |
| CVE-2026-47267 | HIGH | 8.3 | 0.4% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, the fix for CVE-2022-1285 prevents adding webooks or ru... |
| CVE-2026-45687 | HIGH | 8.5 | 0.2% | Jun 24, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, ... |
| CVE-2026-45677 | HIGH | 8.7 | 0.5% | Jun 24, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, ... |
| CVE-2026-33235 | HIGH | 7.7 | 0.3% | Jun 24, 2026 | AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent... |
| CVE-2026-25119 | HIGH | 7.7 | 0.9% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, when ENABLE_REVERSE_PROXY_AUTHENTICATION is enabled, Go... |
| CVE-2026-1840 | HIGH | 8.7 | 0.7% | Jun 24, 2026 | The Aclara Metrum Cellular Web Interface is vulnerable to unauthorized access due to the absence of authentication contr... |
| CVE-2026-13201 | HIGH | 7.3 | 0.1% | Jun 24, 2026 | A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW... |
| CVE-2026-11998 | HIGH | 7.6 | 0.3% | Jun 24, 2026 | A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and ... |
| CVE-2026-55583 | HIGH | 7.6 | 0.2% | Jun 24, 2026 | Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.9.0, Twenty was vulnerable to a cro... |
| CVE-2026-47389 | HIGH | 8.6 | 0.2% | Jun 24, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, when us... |
| CVE-2026-46348 | HIGH | 8.7 | 0.3% | Jun 24, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, the lis... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now