2026 CVE Vulnerabilities
47,874 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45275 | MEDIUM | 6.5 | 0.4% | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability... |
| CVE-2026-40990 | MEDIUM | 6.5 | 0.2% | Jun 1, 2026 | OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Produc... |
| CVE-2026-40989 | MEDIUM | 6.5 | 0.2% | Jun 1, 2026 | Under infinite recursion in the routing layer, request-handling can cause OOM error. Affected Spring Products and Versi... |
| CVE-2026-23638 | MEDIUM | 6.5 | 0.2% | Jun 1, 2026 | Kiteworks is a private data network (PDN). Prior to version 9.3.0, an Insecure Direct Object Reference (IDOR) vulnerabil... |
| CVE-2026-10283 | MEDIUM | 6.3 | 0.3% | Jun 1, 2026 | A vulnerability was detected in Bottelet DaybydayCRM up to 2.2.1. Affected is an unknown function of the component Setti... |
| CVE-2026-10282 | MEDIUM | 5.3 | 0.2% | Jun 1, 2026 | A security vulnerability has been detected in Bottelet DaybydayCRM up to 2.2.1. This impacts the function view of the fi... |
| CVE-2026-10279 | MEDIUM | 6.3 | 1.1% | Jun 1, 2026 | A vulnerability was identified in hiraishikentaro wezterm-mcp 0.1.0. The affected element is an unknown function of the ... |
| CVE-2026-10278 | MEDIUM | 6.3 | 0.3% | Jun 1, 2026 | A vulnerability was determined in ishayoyo excel-mcp up to 1.0.2. Impacted is an unknown function of the file src/index.... |
| CVE-2026-10277 | MEDIUM | 6.3 | 0.3% | Jun 1, 2026 | A vulnerability was found in j3k0 mcp-google-workspace up to 831790e7d5c2663325733d9f5579cc339a267c4c. This issue affect... |
| CVE-2026-10276 | MEDIUM | 6.3 | 0.3% | Jun 1, 2026 | A vulnerability has been found in hekmon8 Jenkins-server-mcp 0.1.0. This vulnerability affects the function jobPath of t... |
| CVE-2026-8643 | MEDIUM | 5.5 | 0.3% | Jun 1, 2026 | pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute ... |
| CVE-2026-45701 | MEDIUM | 6.9 | 0.2% | Jun 1, 2026 | Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.23 and 3.0.6,... |
| CVE-2026-45267 | MEDIUM | 6.5 | 0.3% | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. Prior to version 5.2.6, a missing permissions check allowed ... |
| CVE-2026-45264 | MEDIUM | 4.3 | 0.2% | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18.... |
| CVE-2026-45157 | MEDIUM | 6.3 | 0.2% | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, a... |
| CVE-2026-45153 | MEDIUM | 4.6 | 0.2% | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. From version 33.0.0 to before version 33.1.0, after unlockin... |
| CVE-2026-44740 | MEDIUM | 6.5 | 0.3% | Jun 1, 2026 | Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may ... |
| CVE-2026-42679 | MEDIUM | 6.5 | 0.3% | Jun 1, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mamunur Rashid Classifie... |
| CVE-2026-42676 | MEDIUM | 6.5 | 0.1% | Jun 1, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred allows Stor... |
| CVE-2026-42671 | MEDIUM | 6.5 | 0.2% | Jun 1, 2026 | Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Incorrectly Configured Access Control Securi... |
| CVE-2026-10275 | MEDIUM | 5 | 0.3% | Jun 1, 2026 | A flaw has been found in OpenSC up to 0.26.1. This affects the function test_kpgen_certwrite of the file src/tools/pkcs1... |
| CVE-2026-10274 | MEDIUM | 6.3 | 0.2% | Jun 1, 2026 | A vulnerability was determined in indrasishbanerjee aem-mcp-server up to b5f833aef9b5dfd17a5991b3b18a8a11edbdc583. This ... |
| CVE-2026-10272 | MEDIUM | 6.5 | 0.3% | Jun 1, 2026 | A vulnerability has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The imp... |
| CVE-2026-10271 | MEDIUM | 6.3 | 0.3% | Jun 1, 2026 | A flaw has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The affected ele... |
| CVE-2026-10269 | MEDIUM | 6.3 | 0.3% | Jun 1, 2026 | A security vulnerability has been detected in decolua 9router up to 0.4.0. This issue affects the function isAuthenticat... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now