2026 CVE Vulnerabilities
48,301 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48895 | HIGH | 7.2 | 0.4% | Jun 19, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX. The attacker could manipulate some ... |
| CVE-2026-48141 | HIGH | 7.5 | 0.2% | Jun 19, 2026 | There is a memory leak in NI grpc-device BeginSidebandStream that may result in denial of service due to memory exhausti... |
| CVE-2026-48140 | HIGH | 7.1 | 0.3% | Jun 19, 2026 | There is an unchecked enum cast vulnerability in NI grpc-device BeginSidebandStream that may allow an attacker to trigge... |
| CVE-2026-48139 | HIGH | 8.7 | 0.3% | Jun 19, 2026 | There is a NULL pointer dereference vulnerability in NI grpc-device in the data moniker service that may allow an attack... |
| CVE-2026-48138 | HIGH | 8.7 | 0.3% | Jun 19, 2026 | There is an out-of-bounds read vulnerability in the NI grpc-device streaming API due to a missing bounds check that may ... |
| CVE-2026-47339 | HIGH | 8.1 | 0.3% | Jun 19, 2026 | Incorrect Authorization vulnerability in Apache APISIX. An attacker can capitalise on authz-casdoor plugin under defaul... |
| CVE-2026-39998 | HIGH | 8.8 | 0.4% | Jun 19, 2026 | Improper Input Validation vulnerability in Apache APISIX. The attacker can take advantage of certain configuration in f... |
| CVE-2026-12104 | HIGH | 8.6 | 1.1% | Jun 19, 2026 | OS command injection in the environment and tunnel configuration functionality in SIMA GmbH Bondix through version 1.25.... |
| CVE-2026-56142 | HIGH | 8.8 | 0.4% | Jun 19, 2026 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 privileg... |
| CVE-2026-53915 | HIGH | 8.8 | 0.2% | Jun 19, 2026 | In JetBrains GoLand before 2026.1.3 remote code execution was possible via untrusted project configuration |
| CVE-2026-41156 | HIGH | 7.7 | 0.1% | Jun 19, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of reso... |
| CVE-2026-34192 | HIGH | 7.7 | 0.1% | Jun 19, 2026 | Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an error path leading... |
| CVE-2026-11576 | HIGH | 7.5 | 0.3% | Jun 19, 2026 | The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process t... |
| CVE-2026-46461 | HIGH | 7.8 | 0.1% | Jun 19, 2026 | Dell Server Hardware Manager, versions prior to 3.2.2, contains an Improper Access Control vulnerability. A low privileg... |
| CVE-2026-8806 | HIGH | 8.7 | 0.4% | Jun 19, 2026 | Expected Behavior Violation vulnerability in Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET... |
| CVE-2026-8805 | HIGH | 8.7 | 0.4% | Jun 19, 2026 | Integer Overflow or Wraparound vulnerability in the EtherNet/IP function of Mitsubishi Electric MELSEC iQ-F Series FX5-E... |
| CVE-2026-52866 | HIGH | 7.1 | 0.2% | Jun 19, 2026 | An attacker within BLE communication range can monopolize the device's only available BLE connection slot, preventing l... |
| CVE-2026-50034 | HIGH | 7.1 | 0.1% | Jun 19, 2026 | An attacker within BLE communication range can passively intercept wireless traffic and obtain sensitive health-related... |
| CVE-2026-12050 | HIGH | 8.8 | 0.2% | Jun 19, 2026 | SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/{sid}). The user-sup... |
| CVE-2026-12045 | HIGH | 8.8 | 0.5% | Jun 19, 2026 | Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that th... |
| CVE-2026-12044 | HIGH | 8.8 | 0.5% | Jun 19, 2026 | SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<description>'`` for a user-su... |
| CVE-2026-56078 | HIGH | 8.8 | 0.7% | Jun 18, 2026 | PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent IDs w... |
| CVE-2026-56077 | HIGH | 7.1 | 0.3% | Jun 18, 2026 | PraisonAI before 1.5.115 contains an information disclosure vulnerability in the MultiAgentLedger component that allows ... |
| CVE-2026-56076 | HIGH | 8.6 | 0.5% | Jun 18, 2026 | PraisonAI before 1.5.128 contains a cross-origin agent execution vulnerability in the AGUI endpoint that allows remote a... |
| CVE-2026-56075 | HIGH | 8.8 | 0.5% | Jun 18, 2026 | PraisonAI before 4.5.128 contains an arbitrary shell command execution vulnerability where the UI modules hardcode appro... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now