2026 CVE Vulnerabilities
48,546 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45012 | HIGH | 7.6 | 0.2% | Jun 12, 2026 | ApostropheCMS is an open-source Node.js content management system. Versions up to and including 4.29.0 contain an authen... |
| CVE-2026-45011 | HIGH | 7.3 | 0.2% | Jun 12, 2026 | ApostropheCMS is an open-source Node.js content management system. Version 4.29.0 has a stored cross-site scripting vuln... |
| CVE-2026-44786 | HIGH | 7.5 | 0.3% | Jun 12, 2026 | Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.4, 2026.3.0-latest to be... |
| CVE-2026-54361 | HIGH | 8.8 | 0.3% | Jun 12, 2026 | MISP contained multiple mass assignment vulnerabilities in the handling of collections, tag collections, event delegatio... |
| CVE-2026-54360 | HIGH | 8.4 | 0.2% | Jun 12, 2026 | A mass assignment vulnerability exists in MISP’s sharing group creation endpoint. When creating a new sharing group, the... |
| CVE-2026-54359 | HIGH | 7.1 | 0.2% | Jun 12, 2026 | MISP contains an insecure default configuration in which the Security.check_sec_fetch_site_header control is disabled. W... |
| CVE-2026-54358 | HIGH | 7.5 | 0.2% | Jun 12, 2026 | An incorrect authorization vulnerability in MISP allows an organization administrator to target site administrator accou... |
| CVE-2026-50287 | HIGH | 8.7 | 0.4% | Jun 12, 2026 | AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a ... |
| CVE-2026-47260 | HIGH | 7.7 | 0.3% | Jun 12, 2026 | Koel is a free, open-source music streaming solution. Prior to version 9.3.5, Koel validates the podcast feed URL via th... |
| CVE-2026-42851 | HIGH | 7.8 | 0.2% | Jun 12, 2026 | Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty term... |
| CVE-2026-42850 | HIGH | 8.8 | 0.3% | Jun 12, 2026 | Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, it is possible to inject commands within the ... |
| CVE-2026-53408 | HIGH | 8.1 | 0.2% | Jun 12, 2026 | Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.... |
| CVE-2026-50108 | HIGH | 8.7 | 0.3% | Jun 12, 2026 | The Naxclow platform API that returns device relay registration details exposes a persistent credential without verifyin... |
| CVE-2026-47138 | HIGH | 8.7 | 0.6% | Jun 12, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-42947 | HIGH | 8.8 | 0.3% | Jun 12, 2026 | A flaw in Naxclow's platform’s onboarding workflow allows an attacker to replay a confirm-then-bind sequence to silently... |
| CVE-2026-42306 | HIGH | 7.2 | 0.1% | Jun 12, 2026 | Moby is an open source container framework. In Docker Engine prior to version 29.5.1, Docker Daemon versions 28.5.2 and ... |
| CVE-2026-12143 | HIGH | 7.5 | 0.5% | Jun 12, 2026 | form-data is a library for creating readable multipart/form-data streams. In versions through 4.0.5, the `field` argumen... |
| CVE-2026-12043 | HIGH | 8.8 | 0.4% | Jun 12, 2026 | Improper handling of HPACK dynamic table size updates in the AWS Common Runtime aws-c-http library might allow a remote ... |
| CVE-2026-53406 | HIGH | 7.8 | 0.1% | Jun 12, 2026 | Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.... |
| CVE-2026-48165 | HIGH | 7.2 | 1.3% | Jun 12, 2026 | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before ... |
| CVE-2026-48163 | HIGH | 7.2 | 0.9% | Jun 12, 2026 | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before ... |
| CVE-2026-47965 | HIGH | 7.8 | 0.1% | Jun 12, 2026 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds write vulnerability that... |
| CVE-2026-47216 | HIGH | 8.7 | 0.3% | Jun 12, 2026 | Typesense is a fast, typo-tolerant search engine. Prior to versions 29.1 and 30.2, there is an unauthenticated denial-of... |
| CVE-2026-44171 | HIGH | 7.8 | 0.1% | Jun 12, 2026 | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before ... |
| CVE-2026-44168 | HIGH | 8 | 0.6% | Jun 12, 2026 | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.26, 10.11.1 to before ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now