2026 CVE Vulnerabilities
48,542 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-36213 | HIGH | 7.8 | 0.2% | Jun 15, 2026 | An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.e... |
| CVE-2026-8357 | HIGH | 7.8 | 0.2% | Jun 15, 2026 | LibreOffice Calc compiles cell formulas when opening a spreadsheet. A heap buffer overflow existed when compiling a very... |
| CVE-2026-6040 | HIGH | 7.3 | 0.1% | Jun 15, 2026 | A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read f... |
| CVE-2026-47777 | HIGH | 7.5 | 0.2% | Jun 15, 2026 | Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in ... |
| CVE-2026-9863 | HIGH | 8.8 | 0.6% | Jun 15, 2026 | Fortra BoKS Manager contains an OS command injection vulnerability in the client upgrade and patch tooling for legacy ta... |
| CVE-2026-5038 | HIGH | 7.5 | 0.3% | Jun 15, 2026 | Impact: multer versions 2.0.0-alpha.1 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service when using d... |
| CVE-2026-6517 | HIGH | 7.7 | 0.2% | Jun 15, 2026 | Mattermost Desktop App versions <=6.1 5.5.13.0 fail to restrict the allow list of domains to which NTLM credentials were... |
| CVE-2026-5242 | HIGH | 8.8 | 0.3% | Jun 15, 2026 | Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. Pizzy Library allows Code... |
| CVE-2026-5233 | HIGH | 7.1 | 0.2% | Jun 15, 2026 | Improper Control of Interaction Frequency vulnerability in MIA Technology Inc. Pizzy Library allows Flooding. This issu... |
| CVE-2026-5230 | HIGH | 7.1 | 0.2% | Jun 15, 2026 | Improper Access Control, Missing Authorization vulnerability in MIA Technology Inc. Pizzy Library allows Exploiting Inco... |
| CVE-2026-5079 | HIGH | 7.5 | 0.3% | Jun 15, 2026 | Impact: multer versions 1.0.0 through 2.1.1 and 3.0.0-alpha.1 are vulnerable to a Denial of Service via deeply nested fi... |
| CVE-2026-49111 | HIGH | 8.8 | 0.2% | Jun 15, 2026 | Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation. This issue affe... |
| CVE-2026-49064 | HIGH | 7.5 | 0.2% | Jun 15, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Stiofan GetPaid allows Retrieve Embedded Sensitive Da... |
| CVE-2026-49062 | HIGH | 8.8 | 0.3% | Jun 15, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recovery Ex... |
| CVE-2026-34026 | HIGH | 7.1 | 0.4% | Jun 15, 2026 | Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a path traversal vulnerability in the docume... |
| CVE-2026-34024 | HIGH | 8.6 | 0.3% | Jun 15, 2026 | The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains missing authorization checks on multiple... |
| CVE-2026-34023 | HIGH | 7.1 | 0.3% | Jun 15, 2026 | The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an incorrect authorization vulnerability... |
| CVE-2026-34022 | HIGH | 7.1 | 0.1% | Jun 15, 2026 | The Wertheim SafeController Family 65000, Controller 65000 - AssemblyVersion 6.11.8130.22319, uses weak custom cryptogra... |
| CVE-2026-34021 | HIGH | 8.6 | 0.2% | Jun 15, 2026 | The Wertheim SafeController 5400, Controller 5400 - AssemblyVersion 6.11.8130.22320, uses RS-485 communication between t... |
| CVE-2026-12057 | HIGH | 7.8 | 0.1% | Jun 15, 2026 | When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some d... |
| CVE-2026-50100 | HIGH | 8.5 | 0.1% | Jun 15, 2026 | Multiple printer drivers provided by Ricoh Company, Ltd. and KONICA MINOLTA JAPAN, INC. contain a privilege escalation v... |
| CVE-2026-11860 | HIGH | 7.5 | 0.2% | Jun 15, 2026 | Quick.CMS deserializes user-controlled data received over plaintext HTTP without ensuring integrity or authenticity. Thi... |
| CVE-2026-12222 | HIGH | 8 | 0.4% | Jun 15, 2026 | A vulnerability was determined in Yealink SIP-T46U 108.86.0.118. Affected is the function mod_webd.BlueToothTest of the ... |
| CVE-2026-12221 | HIGH | 8 | 0.4% | Jun 15, 2026 | A vulnerability was found in Yealink SIP-T46U 108.86.0.118. This impacts the function sprintf of the file /api/upgrade/u... |
| CVE-2026-12220 | HIGH | 8 | 0.4% | Jun 15, 2026 | A vulnerability has been found in Yealink SIP-T46U 108.86.0.118. This affects the function mod_upgrade.SparePartsUpload ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now