2026 CVE Vulnerabilities
48,297 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9320 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 a... |
| CVE-2026-9071 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 a... |
| CVE-2026-8858 | HIGH | 8.8 | 0.3% | Jun 22, 2026 | IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution an... |
| CVE-2026-8636 | HIGH | 7.5 | 0.1% | Jun 22, 2026 | IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve use... |
| CVE-2026-56104 | HIGH | 8.8 | 0.3% | Jun 22, 2026 | Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and i... |
| CVE-2026-54268 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-50178 | HIGH | 8.8 | 0.2% | Jun 22, 2026 | The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. the client-side... |
| CVE-2026-49241 | HIGH | 8.8 | 0.2% | Jun 22, 2026 | The Angular Language Service VS Code Extension provides a rich editing experience for Angular templates. Prior to 21.2.4... |
| CVE-2026-41049 | HIGH | 7.1 | 0.1% | Jun 22, 2026 | Incorrect caching of authentication between different users of the qSnapper dbus service before version 1.3.3 allowed a... |
| CVE-2026-41048 | HIGH | 7.1 | 0.1% | Jun 22, 2026 | Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local at... |
| CVE-2026-41046 | HIGH | 7.3 | 0.2% | Jun 22, 2026 | A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to... |
| CVE-2026-41045 | HIGH | 7 | 0.1% | Jun 22, 2026 | A time-to-check-time-of-use in polkit authentication of qSnapper before version 1.3.3 allowed a local attacker to bypass... |
| CVE-2026-10845 | HIGH | 7.3 | 0.3% | Jun 22, 2026 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to bypass authentication and gain unauthorize... |
| CVE-2026-56448 | HIGH | 8.3 | 0.3% | Jun 22, 2026 | A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e4... |
| CVE-2026-56447 | HIGH | 7.2 | 0.3% | Jun 22, 2026 | MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path... |
| CVE-2026-56446 | HIGH | 7.2 | 0.4% | Jun 22, 2026 | MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool... |
| CVE-2026-56425 | HIGH | 8.8 | 0.3% | Jun 22, 2026 | The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorizat... |
| CVE-2026-56424 | HIGH | 8.8 | 0.4% | Jun 22, 2026 | MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong ent... |
| CVE-2026-56423 | HIGH | 8.8 | 0.3% | Jun 22, 2026 | MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The af... |
| CVE-2026-54100 | HIGH | 8.3 | 0.3% | Jun 22, 2026 | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishe... |
| CVE-2026-54099 | HIGH | 8.8 | 0.1% | Jun 22, 2026 | A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR au... |
| CVE-2026-42129 | HIGH | 7.7 | 0.4% | Jun 22, 2026 | A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endp... |
| CVE-2026-28381 | HIGH | 8.1 | 0.2% | Jun 22, 2026 | The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the da... |
| CVE-2026-12602 | HIGH | 8.8 | 0.1% | Jun 22, 2026 | Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assig... |
| CVE-2026-12581 | HIGH | 7.7 | 0.3% | Jun 22, 2026 | EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a s... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now