2026 CVE Vulnerabilities
48,546 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7387 | HIGH | 8.8 | 0.3% | Jun 12, 2026 | Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to req... |
| CVE-2026-6961 | HIGH | 7.6 | 0.3% | Jun 12, 2026 | Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to san... |
| CVE-2026-6739 | HIGH | 7.2 | 0.3% | Jun 12, 2026 | Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 fail to require system-... |
| CVE-2026-53982 | HIGH | 7.1 | 0.3% | Jun 12, 2026 | Cap-go Console < 12.28.2 contains a denial-of-service vulnerability in its account deletion flow that allows an attacker... |
| CVE-2026-53981 | HIGH | 7.6 | 0.3% | Jun 12, 2026 | Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism that allows an attacke... |
| CVE-2026-3840 | HIGH | 7.1 | 0.2% | Jun 12, 2026 | A vulnerability in Kedro version 1.2.0 allows an attacker to exploit path traversal by providing a crafted version strin... |
| CVE-2026-9638 | HIGH | 7.5 | 0.3% | Jun 12, 2026 | Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts. These versions use the built... |
| CVE-2026-8828 | HIGH | 8.8 | 0.3% | Jun 12, 2026 | A lack of authorization validation in version 1.0.0 or later of the ChromaDB Rust project allows any authenticated users... |
| CVE-2026-50091 | HIGH | 7.4 | 0.2% | Jun 12, 2026 | Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses h... |
| CVE-2026-50011 | HIGH | 7.5 | 0.4% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina... |
| CVE-2026-50010 | HIGH | 7.5 | 0.5% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina... |
| CVE-2026-48748 | HIGH | 7.5 | 0.4% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Starting in version 4.2.0.Fina... |
| CVE-2026-48059 | HIGH | 7.5 | 0.6% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina... |
| CVE-2026-48043 | HIGH | 7.5 | 0.6% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to ... |
| CVE-2026-48006 | HIGH | 7.5 | 0.6% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina... |
| CVE-2026-45833 | HIGH | 8.8 | 0.3% | Jun 12, 2026 | A code injection vulnerability in version 0.4.17 or later of the ChromaDB Python project allows an authenticated attacke... |
| CVE-2026-45832 | HIGH | 8.8 | 0.3% | Jun 12, 2026 | All V1 collection-level endpoints in ChromaDB's Python project pass None for the tenant and database to the authorizatio... |
| CVE-2026-45831 | HIGH | 8.8 | 0.2% | Jun 12, 2026 | The SimpleRBACAuthorizationProvider authorization provider in versions 0.5.0 or later of the ChromaDB Python project eva... |
| CVE-2026-45830 | HIGH | 8.8 | 0.3% | Jun 12, 2026 | A lack of authorization validation in version 0.4.17 or later of the ChromaDB Python project allows any authenticated us... |
| CVE-2026-40677 | HIGH | 7.7 | 0.4% | Jun 12, 2026 | The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a man-in-the-middle atta... |
| CVE-2026-7368 | HIGH | 8.6 | 0.3% | Jun 12, 2026 | The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether ... |
| CVE-2026-6211 | HIGH | 8.7 | 0.2% | Jun 12, 2026 | Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Access... |
| CVE-2026-53721 | HIGH | 8.2 | 0.3% | Jun 12, 2026 | Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4... |
| CVE-2026-47209 | HIGH | 8.6 | 0.3% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the BaseHandler.set trap in bridge.js (line 1231)... |
| CVE-2026-47139 | HIGH | 8.6 | 0.3% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding public network builtins... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now