2026 CVE Vulnerabilities
48,516 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-39590 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated Local File Inclusion in Atomlab <= 2.4.5 versions. |
| CVE-2026-39576 | HIGH | 8.1 | 0.4% | Jun 17, 2026 | Unauthenticated PHP Object Injection in SingleMalt <= 1.5 versions. |
| CVE-2026-39560 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Hiroshi <= 1.5.1 versions. |
| CVE-2026-39559 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated Local File Inclusion in Uppercase < 1.2.2 versions. |
| CVE-2026-39556 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Konsept <= 1.9 versions. |
| CVE-2026-39523 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated Local File Inclusion in Solene Core <= 2.3.2 versions. |
| CVE-2026-39445 | HIGH | 8.1 | 0.4% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Alukas < 3.0.0 versions. |
| CVE-2026-39442 | HIGH | 8.1 | 0.3% | Jun 17, 2026 | Unauthenticated PHP Object Injection in PressMart <= 1.2.26 versions. |
| CVE-2026-10641 | HIGH | 7.1 | 0.3% | Jun 17, 2026 | Zephyr's Bluetooth Classic Hands-Free Profile (HFP) Hands-Free role parser (subsys/bluetooth/host/classic/hfp_hf.c) cont... |
| CVE-2026-9690 | HIGH | 7.5 | 0.5% | Jun 17, 2026 | Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions. |
| CVE-2026-9570 | HIGH | 7.1 | 0.1% | Jun 17, 2026 | The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it into inline ... |
| CVE-2026-8089 | HIGH | 7.1 | 0.2% | Jun 17, 2026 | The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin ... |
| CVE-2026-5667 | HIGH | 7.2 | 0.2% | Jun 17, 2026 | Use of Hard-coded Credentials vulnerability in Mitsubishi Electric Room Air Conditioners (for Japan and outside Japan); ... |
| CVE-2026-55706 | HIGH | 8.3 | 0.2% | Jun 17, 2026 | sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values f... |
| CVE-2026-54805 | HIGH | 8.8 | 0.4% | Jun 17, 2026 | Subscriber Privilege Escalation in Falang multilanguage <= 1.4.2 versions. |
| CVE-2026-54804 | HIGH | 7.6 | 0.3% | Jun 17, 2026 | Subscriber Broken Authentication in Melhor Envio <= 2.16.3 versions. |
| CVE-2026-54802 | HIGH | 7.5 | 0.4% | Jun 17, 2026 | Unauthenticated Broken Authentication in SMS Alert Order Notifications <= 3.9.3 versions. |
| CVE-2026-54195 | HIGH | 7.1 | 0.1% | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.0.1 versions. |
| CVE-2026-54192 | HIGH | 7.1 | 0.2% | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in Popup box <= 6.2.9 versions. |
| CVE-2026-54189 | HIGH | 7.1 | 0.1% | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions. |
| CVE-2026-54188 | HIGH | 7.1 | 0.1% | Jun 17, 2026 | Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.10 versions. |
| CVE-2026-54185 | HIGH | 8.5 | 0.3% | Jun 17, 2026 | Subscriber SQL Injection in Cornerstone < 7.8.8 versions. |
| CVE-2026-54184 | HIGH | 8.2 | 0.3% | Jun 17, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Clean Login <= 1.15 versions. |
| CVE-2026-53876 | HIGH | 8.6 | 1.8% | Jun 17, 2026 | RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may lead to arbitrary c... |
| CVE-2026-52698 | HIGH | 7.4 | 0.2% | Jun 17, 2026 | Subscriber Sensitive Data Exposure in PushEngage – Web Push Notifications, eCommerce Automation & Chat Widget <= 4.2... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now