2026 CVE Vulnerabilities
48,299 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48774 | HIGH | 7.5 | 0.4% | Jun 19, 2026 | ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 3.0.0 through 3.0.8, ProxySQL's GenAI/MC... |
| CVE-2026-48715 | HIGH | 8.8 | 0.2% | Jun 19, 2026 | radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the `radvdump` utility shipped with radvd contai... |
| CVE-2026-48089 | HIGH | 7.1 | 0.2% | Jun 19, 2026 | DevGuard provides vulnerability management for the full software supply chain. Prior to 1.4.2, on a DevGuard API instanc... |
| CVE-2026-49340 | HIGH | 8.1 | 0.3% | Jun 19, 2026 | gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, a logic e... |
| CVE-2026-49339 | HIGH | 7.1 | 0.3% | Jun 19, 2026 | gonic is a music streaming server / free-software subsonic server API implementation. The maintainer's fix in commit `6... |
| CVE-2026-49338 | HIGH | 7.1 | 0.2% | Jun 19, 2026 | gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, the Subso... |
| CVE-2026-49293 | HIGH | 7.5 | 0.3% | Jun 19, 2026 | js-toml is a TOML parser for JavaScript, fully compliant with the TOML 1.0.0 Spec. Versions up to and including 1.1.0 pa... |
| CVE-2026-49291 | HIGH | 8.1 | 0.3% | Jun 19, 2026 | mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpo... |
| CVE-2026-49290 | HIGH | 7.6 | 0.6% | Jun 19, 2026 | Slopsmith is a self-contained web application for browsing, playing, and practicing Rocksmith 2014 Custom DLC (CDLC). Pr... |
| CVE-2026-49287 | HIGH | 7.4 | 0.3% | Jun 19, 2026 | Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.23 and 6.20.0, the fix for CVE-2026... |
| CVE-2026-49286 | HIGH | 8.1 | 0.6% | Jun 19, 2026 | PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/... |
| CVE-2026-56211 | HIGH | 7.1 | 0.5% | Jun 19, 2026 | A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds v... |
| CVE-2026-56210 | HIGH | 7.1 | 0.3% | Jun 19, 2026 | A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds ... |
| CVE-2026-56209 | HIGH | 7.1 | 0.3% | Jun 19, 2026 | An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds c... |
| CVE-2026-56208 | HIGH | 7.6 | 0.3% | Jun 19, 2026 | A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 enco... |
| CVE-2026-49260 | HIGH | 8.2 | 0.2% | Jun 19, 2026 | PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.5.1, `pontedilana/... |
| CVE-2026-3195 | HIGH | 7.4 | 0.1% | Jun 19, 2026 | A flaw was found in QEMU. When reading input audio in the virtio-snd device input callback, the `virtio_snd_pcm_in_cb` f... |
| CVE-2026-52910 | HIGH | 7.8 | 0.1% | Jun 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Free reuseport cBPF prog after RCU grace perio... |
| CVE-2026-52909 | HIGH | 7.8 | 0.1% | Jun 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: ip6_vti: set netns_immutable on the fallback device... |
| CVE-2026-52908 | HIGH | 7.8 | 0.1% | Jun 19, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA: During rereg_mr ensure that REREG_ACCESS is c... |
| CVE-2026-4027 | HIGH | 7.1 | 0.2% | Jun 19, 2026 | A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 and R2 that could allow unauthorized acces... |
| CVE-2026-4026 | HIGH | 8.7 | 0.3% | Jun 19, 2026 | A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 that could allow an authenticated user wit... |
| CVE-2026-49872 | HIGH | 8.1 | 0.3% | Jun 19, 2026 | Improper Authentication vulnerability in Apache APISIX. When the cas-auth plugin is used in a route, an attacker can po... |
| CVE-2026-49357 | HIGH | 8.8 | 0.3% | Jun 19, 2026 | Line Desktop MCP is a project that, while unaffiliated with the official line-bot-mcp-server, allows users to directly o... |
| CVE-2026-48895 | HIGH | 7.2 | 0.4% | Jun 19, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now