2026 CVE Vulnerabilities
48,334 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48764 | HIGH | 8.2 | 0.3% | Jun 18, 2026 | TypeBot is a chatbot builder tool. In versions prior to 3.17.2, SSRF validation is implemented by resolving a hostname o... |
| CVE-2026-53676 | HIGH | 8.6 | 0.6% | Jun 17, 2026 | ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed c... |
| CVE-2026-48759 | HIGH | 7.1 | 0.2% | Jun 17, 2026 | TypeBot is a chatbot builder tool. Versions 3.15.2 and below have an Insecure Direct Object Reference vulnerability thro... |
| CVE-2026-45617 | HIGH | 7.5 | 0.4% | Jun 17, 2026 | LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below,... |
| CVE-2026-45357 | HIGH | 7.5 | 0.4% | Jun 17, 2026 | LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below,... |
| CVE-2026-8050 | HIGH | 7.5 | 0.3% | Jun 17, 2026 | In SignalRGB versions prior to 1.3.7.0, seven of the thirteen IOCTL handlers dereference the SystemBuffer pointer withou... |
| CVE-2026-50200 | HIGH | 7.5 | 0.2% | Jun 17, 2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati... |
| CVE-2026-50196 | HIGH | 7.5 | 0.3% | Jun 17, 2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati... |
| CVE-2026-50194 | HIGH | 8.2 | 0.2% | Jun 17, 2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati... |
| CVE-2026-48997 | HIGH | 7.1 | 0.7% | Jun 17, 2026 | e107 is a content management system (CMS). Versions 2.3.5 and earlier contain a command injection vulnerability in the ... |
| CVE-2026-48989 | HIGH | 8.9 | 0.4% | Jun 17, 2026 | Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP m... |
| CVE-2026-12530 | HIGH | 8.4 | 0.3% | Jun 17, 2026 | Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK vers... |
| CVE-2026-49133 | HIGH | 7.1 | 0.3% | Jun 17, 2026 | Typemill before 2.24.0 contains a path traversal vulnerability that allows authenticated attackers with Author-level pri... |
| CVE-2026-48979 | HIGH | 7.5 | 0.3% | Jun 17, 2026 | PHP Standard Library (PSL) is set of APIs covering async, collections, networking, I/O, cryptography, terminal UI, etc. ... |
| CVE-2026-55202 | HIGH | 8.8 | 0.3% | Jun 17, 2026 | Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection,... |
| CVE-2026-55201 | HIGH | 7.4 | 0.3% | Jun 17, 2026 | Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the download_dir() function ... |
| CVE-2026-55200 | HIGH | 8.3 | 0.7% | Jun 17, 2026 | libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() t... |
| CVE-2026-55199 | HIGH | 7.5 | 0.4% | Jun 17, 2026 | libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SS... |
| CVE-2026-50107 | HIGH | 8.6 | 0.5% | Jun 17, 2026 | When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulnerabilit... |
| CVE-2026-32682 | HIGH | 7.1 | 0.3% | Jun 17, 2026 | When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or... |
| CVE-2026-12529 | HIGH | 7.3 | 0.3% | Jun 17, 2026 | A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1... |
| CVE-2026-11407 | HIGH | 8.6 | 0.6% | Jun 17, 2026 | Pimcore CMS/DXP version 12.3.8 contains a sandbox bypass vulnerability that allows authenticated administrative attacker... |
| CVE-2026-10696 | HIGH | 7.5 | 0.3% | Jun 17, 2026 | Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier all... |
| CVE-2026-55198 | HIGH | 7.1 | 0.3% | Jun 17, 2026 | Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows a... |
| CVE-2026-55197 | HIGH | 7.1 | 0.3% | Jun 17, 2026 | Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows aut... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now