2026 CVE Vulnerabilities
48,366 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-55202 | HIGH | 8.8 | 0.3% | Jun 17, 2026 | Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection,... |
| CVE-2026-55201 | HIGH | 7.4 | 0.3% | Jun 17, 2026 | Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the download_dir() function ... |
| CVE-2026-55200 | HIGH | 8.3 | 0.7% | Jun 17, 2026 | libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() t... |
| CVE-2026-55199 | HIGH | 7.5 | 0.4% | Jun 17, 2026 | libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SS... |
| CVE-2026-50107 | HIGH | 8.6 | 0.5% | Jun 17, 2026 | When NGINX Plus or NGINX Open Source is configured as the data plane for NGINX Gateway Fabric, an injection vulnerabilit... |
| CVE-2026-32682 | HIGH | 7.1 | 0.3% | Jun 17, 2026 | When NGINX Gateway Fabric is configured using GRPCRoutes, an authenticated, remote attacker with permission to create or... |
| CVE-2026-12529 | HIGH | 7.3 | 0.3% | Jun 17, 2026 | A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1... |
| CVE-2026-11407 | HIGH | 8.6 | 0.6% | Jun 17, 2026 | Pimcore CMS/DXP version 12.3.8 contains a sandbox bypass vulnerability that allows authenticated administrative attacker... |
| CVE-2026-10696 | HIGH | 7.5 | 0.3% | Jun 17, 2026 | Use of an incorrectly resolved name or reference in the pinget backend in Devolutions UniGetUI 2026.2.0 and earlier all... |
| CVE-2026-55198 | HIGH | 7.1 | 0.3% | Jun 17, 2026 | Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows a... |
| CVE-2026-55197 | HIGH | 7.1 | 0.3% | Jun 17, 2026 | Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows aut... |
| CVE-2026-53871 | HIGH | 8.6 | 0.4% | Jun 17, 2026 | Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that ac... |
| CVE-2026-53869 | HIGH | 8.7 | 0.6% | Jun 17, 2026 | Hermes Agent before 0.16.0 contains a DNS rebinding vulnerability in WebSocket endpoints that allows remote attackers to... |
| CVE-2026-48818 | HIGH | 7.5 | 0.4% | Jun 17, 2026 | Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and earlier, StaticFiles on Windows is vulnerable t... |
| CVE-2026-9697 | HIGH | 7.4 | 0.5% | Jun 17, 2026 | Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or s... |
| CVE-2026-6734 | HIGH | 8.8 | 0.3% | Jun 17, 2026 | Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying t... |
| CVE-2026-47774 | HIGH | 7.5 | 0.8% | Jun 17, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to versions 1.35.11, 1.36.7... |
| CVE-2026-30802 | HIGH | 8.2 | 0.3% | Jun 17, 2026 | Out-of-bounds Read vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This issue affects Connex... |
| CVE-2026-30799 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Missing Authentication for Critical Function vulnerability in RTI Connext Professional (Security Plugins) allows Identit... |
| CVE-2026-2674 | HIGH | 8.1 | 0.1% | Jun 17, 2026 | Out-of-bounds Write, Out-of-bounds Write, Out-of-bounds Write vulnerability in RTI Connext Professional (Queueing Servic... |
| CVE-2026-2467 | HIGH | 8.1 | 0.2% | Jun 17, 2026 | Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Variables and Tags... |
| CVE-2026-9675 | HIGH | 7.5 | 0.4% | Jun 17, 2026 | Impact: The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of fragme... |
| CVE-2026-53875 | HIGH | 7.1 | 0.4% | Jun 17, 2026 | picklescan before 1.0.3 contains a scanning bypass vulnerability in the scan_pytorch function that allows attackers to e... |
| CVE-2026-53872 | HIGH | 8.7 | 0.5% | Jun 17, 2026 | picklescan before 0.0.35 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to r... |
| CVE-2026-35069 | HIGH | 8 | 0.2% | Jun 17, 2026 | Dell PowerFlex Manager, version(s) prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now