2026 CVE Vulnerabilities
47,770 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35718 | MEDIUM | 6.5 | 0.7% | Jun 2, 2026 | A path traversal vulnerability in the /admin/downloadMedias.cgi endpoint of VIVOTEK INC FD8136-VVTK firmware 0300a allow... |
| CVE-2026-35716 | MEDIUM | 6.3 | 0.3% | Jun 2, 2026 | A stack-based buffer overflow in the motion_privacy.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows authe... |
| CVE-2026-34460 | MEDIUM | 5.4 | 0.1% | Jun 2, 2026 | NamelessMC is website software for Minecraft servers. In versions 2.2.4 and prior, the OAuth callback handling does not ... |
| CVE-2026-7313 | MEDIUM | 4.9 | 0.3% | Jun 2, 2026 | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 ... |
| CVE-2026-49782 | MEDIUM | 5.4 | 0.1% | Jun 2, 2026 | Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Acce... |
| CVE-2026-43965 | MEDIUM | 5.6 | 0.2% | Jun 2, 2026 | Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/pa... |
| CVE-2026-42795 | MEDIUM | 5.1 | 0.1% | Jun 2, 2026 | Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in th... |
| CVE-2026-41918 | MEDIUM | 5.9 | 0.2% | Jun 2, 2026 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions < V4.0). The affected applicatio... |
| CVE-2026-35717 | MEDIUM | 6.3 | 0.3% | Jun 2, 2026 | A stack-based buffer overflow in the export_language.cgi binary in VIVOTEK FD8136 firmware FD8136-VVTK-0300a allows auth... |
| CVE-2026-32685 | MEDIUM | 4.6 | 0.2% | Jun 2, 2026 | Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file read and file write... |
| CVE-2026-32250 | MEDIUM | 4.3 | 0.2% | Jun 2, 2026 | NamelessMC is website software for Minecraft servers. A Reflected Cross-Site Scripting (XSS) vulnerability was discovere... |
| CVE-2026-28116 | MEDIUM | 5.9 | 0.1% | Jun 2, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Emilia Projects Pr... |
| CVE-2026-27351 | MEDIUM | 5.4 | 0.2% | Jun 2, 2026 | Missing Authorization vulnerability in Sekander Badsha Crew HRM allows Exploiting Incorrectly Configured Access Control ... |
| CVE-2026-8993 | MEDIUM | 6.5 | 0.2% | Jun 2, 2026 | D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Applicatio... |
| CVE-2026-5191 | MEDIUM | 5.4 | 0.1% | Jun 2, 2026 | The Tiled Gallery Carousel Without JetPack plugin for WordPress is vulnerable to stored cross-site scripting via the 'da... |
| CVE-2026-46718 | MEDIUM | 6.5 | 0.4% | Jun 2, 2026 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite. Thi... |
| CVE-2026-41115 | MEDIUM | 4.3 | 0.3% | Jun 2, 2026 | An improper authorization vulnerability has been identified in Apache Kafka. The implementation of the CONSUMER_GROUP_D... |
| CVE-2026-34907 | MEDIUM | 5.1 | 0.3% | Jun 2, 2026 | Wirtualna Uczelnia is vulnerable to Reflected Cross‑Site Scripting (XSS) due to insecure handling of the locale paramete... |
| CVE-2026-10549 | MEDIUM | 5.3 | 0.3% | Jun 2, 2026 | LDAP filter injection vulnerability in Yandex Database prior to 25.3.1.25 allows a remote attacker with valid LDAP crede... |
| CVE-2026-9730 | MEDIUM | 4.3 | 0.1% | Jun 2, 2026 | The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to... |
| CVE-2026-9723 | MEDIUM | 4.3 | 0.1% | Jun 2, 2026 | The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2026-9722 | MEDIUM | 4.3 | 0.1% | Jun 2, 2026 | The Laiser Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.... |
| CVE-2026-9599 | MEDIUM | 4.3 | 0.1% | Jun 2, 2026 | The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,... |
| CVE-2026-9234 | MEDIUM | 4.3 | 0.2% | Jun 2, 2026 | The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and inc... |
| CVE-2026-8885 | MEDIUM | 6.4 | 0.2% | Jun 2, 2026 | The DeMomentSomTres Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'callo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now