2026 CVE Vulnerabilities
48,325 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44691 | HIGH | 8.8 | 0.2% | Jun 18, 2026 | In Eclipse Theia versions prior to 1.69.0, custom task definitions in workspace files (e.g. .theia/tasks.json, .vscode/t... |
| CVE-2026-44688 | HIGH | 8.8 | 0.3% | Jun 18, 2026 | In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory names as part of its... |
| CVE-2026-8461 | HIGH | 8.8 | 0.5% | Jun 18, 2026 | An out-of-bounds write vulnerability in FFmpeg's libavcodec library, specifically in the MagicYUV decoder, allows denial... |
| CVE-2026-56012 | HIGH | 8.5 | 0.2% | Jun 18, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Medi... |
| CVE-2026-54224 | HIGH | 7.1 | 0.3% | Jun 18, 2026 | UBB.threads is vulnerable to Denial of Service (DoS). By sending multiple concurrent requests to view any user profile o... |
| CVE-2026-54223 | HIGH | 8.6 | 0.6% | Jun 18, 2026 | UBB.threads is vulnerable to Path traversal, allowing attackers with privilege to edit templates to read and write any f... |
| CVE-2026-54222 | HIGH | 8.6 | 0.3% | Jun 18, 2026 | UBB.threads is vulnerable to Blind SQL Injection, allowing attackers with access to the Members in Control Panel to inte... |
| CVE-2026-54220 | HIGH | 8.6 | 0.2% | Jun 18, 2026 | uBB.threads is vulnerable to a Cross-Site Request Forgery (CSRF) due to a lack of protective mechanisms. This allows an ... |
| CVE-2026-50141 | HIGH | 7.1 | 0.2% | Jun 18, 2026 | Woodpecker is a CI/CD engine. Starting in version 3.0.0 and prior to version 3.14.1, a vulnerability in Woodpecker CI's ... |
| CVE-2026-42488 | HIGH | 8.1 | 0.4% | Jun 18, 2026 | Some shadow paging errors paths will switch the page-tables without updating the currently running vCPU reference. This... |
| CVE-2026-42487 | HIGH | 7.9 | 0.1% | Jun 18, 2026 | HVM guest I/O port accesses are subject to either emulation or at least translation. Translations are managed by the de... |
| CVE-2026-40456 | HIGH | 8.6 | 0.9% | Jun 18, 2026 | An OS Command Injection vulnerability exists in LMS (LAN Management System) before commit 9fcb4de due to an IP address p... |
| CVE-2026-40455 | HIGH | 8.6 | 0.2% | Jun 18, 2026 | An SQL Injection vulnerability exists in LMS (LAN Management System) before commit 4cb30a7 within the "tarifflist.php" m... |
| CVE-2026-11958 | HIGH | 7.3 | 0.1% | Jun 18, 2026 | Local privilege escalation by loading DLLs from a shared temporary directory in ANSSI’s DFIR-ORC, versions 10.2.7 and pr... |
| CVE-2026-11719 | HIGH | 8.1 | 0.1% | Jun 18, 2026 | An authenticated authorization bypass vulnerability exists in MCP Toolbox for Databases due to missing scope enforcement... |
| CVE-2026-8811 | HIGH | 7.1 | 0.3% | Jun 18, 2026 | SEPPmail versions before 15.0.5 allow improper handling of attachment filenames during encrypted PDF generation. An atta... |
| CVE-2026-55746 | HIGH | 7.6 | 0.2% | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to stored Cross-Site Scripting in the Personal File Storage... |
| CVE-2026-55744 | HIGH | 8.6 | 0.2% | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the Personal File Storage ... |
| CVE-2026-55741 | HIGH | 8.8 | 0.2% | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration configu... |
| CVE-2026-11395 | HIGH | 7.2 | 0.2% | Jun 18, 2026 | The CF7 to Webhook plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and includin... |
| CVE-2026-9860 | HIGH | 8.8 | 0.6% | Jun 18, 2026 | The Offload, AI & Optimize with Cloudflare Images plugin for WordPress is vulnerable to Remote Code Execution in all ver... |
| CVE-2026-12505 | HIGH | 7.8 | 0.2% | Jun 18, 2026 | A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges befor... |
| CVE-2026-12407 | HIGH | 8.8 | 0.4% | Jun 18, 2026 | The E2Pdf – Export Pdf Tool for WordPress plugin for WordPress is vulnerable to Missing Authorization in versions up to,... |
| CVE-2026-48764 | HIGH | 8.2 | 0.3% | Jun 18, 2026 | TypeBot is a chatbot builder tool. In versions prior to 3.17.2, SSRF validation is implemented by resolving a hostname o... |
| CVE-2026-53676 | HIGH | 8.6 | 0.6% | Jun 17, 2026 | ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed c... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now