2026 CVE Vulnerabilities
48,280 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-52953 | HIGH | 7.1 | 0.1% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix oops due to out of scope access Be... |
| CVE-2026-52952 | HIGH | 8.8 | 0.1% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: iommu: Fix WARN_ON in __iommu_group_set_domain_nofa... |
| CVE-2026-52951 | HIGH | 7.8 | 0.1% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/dma-buf: handle empty bo and UAF races Ther... |
| CVE-2026-52950 | HIGH | 7.8 | 0.1% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/xe/dma-buf: fix UAF with retry loop Retry does... |
| CVE-2026-52947 | HIGH | 7.8 | 0.1% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: qrtr: fix refcount saturation and potential UA... |
| CVE-2026-52946 | HIGH | 7.5 | 0.5% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync s... |
| CVE-2026-52945 | HIGH | 7.5 | 0.3% | Jun 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: Revert "wireguard: device: enable threaded NAPI" T... |
| CVE-2026-13164 | HIGH | 8.8 | 0.4% | Jun 24, 2026 | Missing Authentication for Critical Function (CWE-306) in the RegisterView (apps/accounts/views.py), exposed at POST /ap... |
| CVE-2026-55488 | HIGH | 7.7 | 0.6% | Jun 24, 2026 | motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program w... |
| CVE-2026-49269 | HIGH | 8.6 | 0.3% | Jun 24, 2026 | Apple M1 GPUs retain register file data between compute shader dispatches from different processes. A sandboxed Metal at... |
| CVE-2026-12986 | HIGH | 7.3 | 0.2% | Jun 24, 2026 | A critical vulnerability in Admin GUI in Payara Server Full 4.x, 5.x, 6.x, 7.x, 7.2026.x, 6.2025.x, 6.2024.x on All plat... |
| CVE-2026-11877 | HIGH | 7.5 | 0.2% | Jun 24, 2026 | An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager. This issue aff... |
| CVE-2026-57303 | HIGH | 7.1 | 0.2% | Jun 24, 2026 | Jenkins Assembla Plugin 1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks, ... |
| CVE-2026-57301 | HIGH | 8.8 | 0.4% | Jun 24, 2026 | Jenkins OWASP ZAP Plugin 1.0.7 and earlier performs build operations on the Jenkins controller rather than the assigned ... |
| CVE-2026-57296 | HIGH | 8.8 | 0.6% | Jun 24, 2026 | Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom works... |
| CVE-2026-57281 | HIGH | 7.5 | 0.6% | Jun 24, 2026 | Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carr... |
| CVE-2026-57280 | HIGH | 8.8 | 0.4% | Jun 24, 2026 | Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not intercept the implicit type casts applied to the ... |
| CVE-2026-42450 | HIGH | 8.4 | 0.1% | Jun 24, 2026 | OpenColorIO is a color management framework for visual effects and animation. Prior to version 2.5.2, `FileFormatSpi3D.c... |
| CVE-2026-35025 | HIGH | 8.6 | 0.3% | Jun 24, 2026 | ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users... |
| CVE-2026-12537 | HIGH | 7.8 | 0.3% | Jun 24, 2026 | Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) ... |
| CVE-2026-56370 | HIGH | 7.8 | 0.1% | Jun 24, 2026 | ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing... |
| CVE-2026-56368 | HIGH | 7.5 | 0.2% | Jun 24, 2026 | ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allo... |
| CVE-2026-56270 | HIGH | 7.5 | 0.4% | Jun 24, 2026 | Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginm... |
| CVE-2026-56257 | HIGH | 7.1 | 0.2% | Jun 24, 2026 | Capgo before 12.128.2 allows direct patching of public.apps.owner_org through PostgREST, bypassing the transfer_app() wo... |
| CVE-2026-56256 | HIGH | 7.1 | 0.2% | Jun 24, 2026 | Capgo before 12.128.2 enforces mandatory two-factor authentication only at the UI level. Sensitive Organization (ORG) ma... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now