2026 CVE Vulnerabilities
48,542 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53704 | HIGH | 7.1 | 0.2% | Jun 15, 2026 | A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file cont... |
| CVE-2026-53703 | HIGH | 7.1 | 0.2% | Jun 15, 2026 | A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file,... |
| CVE-2026-52722 | HIGH | 7.1 | 0.4% | Jun 15, 2026 | A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor d... |
| CVE-2026-52720 | HIGH | 8.8 | 0.6% | Jun 15, 2026 | A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorr... |
| CVE-2026-52719 | HIGH | 7.1 | 0.3% | Jun 15, 2026 | An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser rea... |
| CVE-2026-50891 | HIGH | 8.1 | 0.3% | Jun 15, 2026 | Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges ... |
| CVE-2026-50889 | HIGH | 7.5 | 0.5% | Jun 15, 2026 | An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (... |
| CVE-2026-50888 | HIGH | 8.1 | 0.2% | Jun 15, 2026 | An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillec... |
| CVE-2026-50885 | HIGH | 7.5 | 0.3% | Jun 15, 2026 | Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attackers to... |
| CVE-2026-50884 | HIGH | 8.8 | 0.3% | Jun 15, 2026 | Incorrect access control in statping-ng v0.93.0 allows attackers to escalate privileges to Administrator and access sens... |
| CVE-2026-50882 | HIGH | 7.5 | 0.3% | Jun 15, 2026 | An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Denial of Service (DoS)... |
| CVE-2026-50881 | HIGH | 8.1 | 0.2% | Jun 15, 2026 | Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate p... |
| CVE-2026-50879 | HIGH | 7.5 | 0.3% | Jun 15, 2026 | An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Ser... |
| CVE-2026-50878 | HIGH | 7.5 | 0.4% | Jun 15, 2026 | An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Serv... |
| CVE-2026-50877 | HIGH | 7.5 | 0.6% | Jun 15, 2026 | An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory traversal via supplying files with names cont... |
| CVE-2026-50875 | HIGH | 8.1 | 0.3% | Jun 15, 2026 | Incorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows authenticated attackers... |
| CVE-2026-50874 | HIGH | 8.1 | 1.1% | Jun 15, 2026 | An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscence v0.3.0 allo... |
| CVE-2026-50870 | HIGH | 7.5 | 0.3% | Jun 15, 2026 | An information disclosure vulnerability in the configuration endpoint of Ben Busby whoogle-search v1.2.3 allows attacker... |
| CVE-2026-49954 | HIGH | 8.6 | 0.5% | Jun 15, 2026 | Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that allows authenticated a... |
| CVE-2026-47835 | HIGH | 7.5 | 0.3% | Jun 15, 2026 | In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearc... |
| CVE-2026-45389 | HIGH | 7.4 | 0.2% | Jun 15, 2026 | In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client ... |
| CVE-2026-41708 | HIGH | 7.5 | 0.3% | Jun 15, 2026 | In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service ... |
| CVE-2026-39118 | HIGH | 8.4 | 0.1% | Jun 15, 2026 | An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client valid... |
| CVE-2026-39007 | HIGH | 7.5 | 0.4% | Jun 15, 2026 | An issue in Observeinc's Observe v.2026-01-28 and before allows a remote attacker to obtain sensitive information via th... |
| CVE-2026-36670 | HIGH | 8.8 | 0.4% | Jun 15, 2026 | A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) pr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now