2026 CVE Vulnerabilities
48,299 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12780 | HIGH | 7.8 | 0.1% | Jun 21, 2026 | A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted is an unknown function in the library amwrtdrv.s... |
| CVE-2026-12779 | HIGH | 7.8 | 0.1% | Jun 21, 2026 | A vulnerability was found in AOMEI Dynamic Disk Manager up to 10.10.1. This issue affects some unknown processing in the... |
| CVE-2026-12778 | HIGH | 7.8 | 0.1% | Jun 21, 2026 | A vulnerability has been found in AOMEI Partition Assistant up to 10.10.1. This vulnerability affects unknown code in th... |
| CVE-2026-12775 | HIGH | 7.3 | 0.3% | Jun 21, 2026 | A vulnerability was detected in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. Affecte... |
| CVE-2026-12771 | HIGH | 7.5 | 0.3% | Jun 21, 2026 | A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/pro... |
| CVE-2026-12770 | HIGH | 8.8 | 0.3% | Jun 21, 2026 | A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file ... |
| CVE-2026-56341 | HIGH | 8.7 | 0.3% | Jun 20, 2026 | AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authori... |
| CVE-2026-56340 | HIGH | 7.5 | 0.4% | Jun 20, 2026 | vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because P... |
| CVE-2026-11912 | HIGH | 7.5 | 0.4% | Jun 20, 2026 | The Simple File List plugin for WordPress is vulnerable to arbitrary file modification due to insufficient authorization... |
| CVE-2026-11911 | HIGH | 7.5 | 0.8% | Jun 20, 2026 | The Simple File List plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validat... |
| CVE-2026-9843 | HIGH | 8.1 | 0.7% | Jun 20, 2026 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to arbitrary file deletion ... |
| CVE-2026-56216 | HIGH | 8.8 | 0.3% | Jun 20, 2026 | Capgo before 12.128.2 contains a scope escalation vulnerability in the POST /functions/v1/apikey endpoint that allows ap... |
| CVE-2026-56215 | HIGH | 8.7 | 0.2% | Jun 20, 2026 | Capgo before 12.128.12 allows authenticated users to modify their mutable public.users.email to arbitrary addresses, whi... |
| CVE-2026-56214 | HIGH | 8.7 | 0.3% | Jun 20, 2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in Supabase PostgREST RPC endpoints is_trial_org ... |
| CVE-2026-56082 | HIGH | 8.7 | 0.2% | Jun 19, 2026 | Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST... |
| CVE-2026-56079 | HIGH | 7.1 | 0.2% | Jun 19, 2026 | Capgo before 12.128.2 contains a cross-tenant authorization bypass vulnerability in PostgREST endpoints that allows org-... |
| CVE-2026-50559 | HIGH | 7.5 | 0.5% | Jun 19, 2026 | Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, ... |
| CVE-2026-50519 | HIGH | 7.5 | 0.5% | Jun 19, 2026 | Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized at... |
| CVE-2026-49346 | HIGH | 7.1 | 0.2% | Jun 19, 2026 | libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream wi... |
| CVE-2026-49295 | HIGH | 7.1 | 0.2% | Jun 19, 2026 | libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream c... |
| CVE-2026-48584 | HIGH | 8.8 | 0.5% | Jun 19, 2026 | Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a networ... |
| CVE-2026-47645 | HIGH | 8.8 | 0.4% | Jun 19, 2026 | Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized atta... |
| CVE-2026-42895 | HIGH | 7.5 | 0.4% | Jun 19, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut... |
| CVE-2026-49344 | HIGH | 7.1 | 0.3% | Jun 19, 2026 | Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, ... |
| CVE-2026-48787 | HIGH | 7.4 | 0.5% | Jun 19, 2026 | gin-vue-admin is an AI-assisted basic development platform. In version 2.9.1, an authenticated attacker with access to t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now