2026 CVE Vulnerabilities
48,546 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47135 | HIGH | 8.7 | 0.3% | Jun 12, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, Symbol.for override in setup-sandbox.js only inte... |
| CVE-2026-46340 | HIGH | 7.5 | 0.4% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport... |
| CVE-2026-45416 | HIGH | 7.5 | 0.9% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina... |
| CVE-2026-44894 | HIGH | 7.5 | 0.1% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. NoQuicTokenHandler is the toke... |
| CVE-2026-44893 | HIGH | 7.5 | 0.6% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. In netty-codec-haproxy prior t... |
| CVE-2026-28980 | HIGH | 8.7 | — | Jun 12, 2026 | ### Summary The `HTTPDecoder` in `NIOHTTP1` enforces no limit on the total size of an HTTP/1 message's header block or ... |
| CVE-2026-43671 | HIGH | 8.3 | — | Jun 12, 2026 | ### Summary A program using swift-nio is vulnerable to a potential out-of-bounds write when attacker-controlled index o... |
| CVE-2026-12066 | HIGH | 7.3 | 0.3% | Jun 12, 2026 | A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the fi... |
| CVE-2026-11967 | HIGH | 8.5 | 0.1% | Jun 12, 2026 | MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading a ma... |
| CVE-2026-11879 | HIGH | 8.5 | 0.1% | Jun 12, 2026 | MobaXterm Personal Edition (Portable), in its 26.3 version (Build 5154), allows arbitrary code execution by loading mali... |
| CVE-2026-47197 | HIGH | 7.2 | 0.2% | Jun 12, 2026 | Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, a moderator with the relevant Discord permission bit can... |
| CVE-2026-47196 | HIGH | 8.4 | 0.2% | Jun 12, 2026 | Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the automod add command trims user input but does not re... |
| CVE-2026-47195 | HIGH | 7.1 | 0.2% | Jun 12, 2026 | Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the purge and slowmode commands check only guild-level p... |
| CVE-2026-9266 | HIGH | 7 | 0.1% | Jun 12, 2026 | A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial... |
| CVE-2026-11848 | HIGH | 7.9 | 0.3% | Jun 12, 2026 | The iRM-IEI Remote Management developed by IEI Integration Corp has a Missing Authentication vulnerability, allowing una... |
| CVE-2026-50645 | HIGH | 7.5 | 0.5% | Jun 12, 2026 | There is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache... |
| CVE-2026-50633 | HIGH | 8.1 | 0.9% | Jun 12, 2026 | A JNDI Injection vulnerability has been discovered in Apache CXF's JCA integration module, which can allow for code exec... |
| CVE-2026-50632 | HIGH | 8.1 | 0.6% | Jun 12, 2026 | A further incomplete fix for a previous advisory CVE-2026-44417 (Untrusted JMS configuration can lead to RCE) for Apache... |
| CVE-2026-50631 | HIGH | 7.4 | 0.3% | Jun 12, 2026 | A race condition in AbstractOAuthDataProvider allows concurrent requests using the same Refresh Token to bypass single-u... |
| CVE-2026-11846 | HIGH | 8.1 | 0.4% | Jun 12, 2026 | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has an Arbitrary File Deletion vulnerabilit... |
| CVE-2026-11845 | HIGH | 8.6 | 1.0% | Jun 12, 2026 | The iVEC-IEI Virtualization Edge Computer developed by IEI Integration Corp has a OS Command Injection vulnerability, al... |
| CVE-2026-12059 | HIGH | 8.8 | 0.4% | Jun 12, 2026 | The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability, allowing authenticated ... |
| CVE-2026-45169 | HIGH | 8.6 | 0.3% | Jun 12, 2026 | Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a v... |
| CVE-2026-44892 | HIGH | 7.5 | 0.3% | Jun 12, 2026 | Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final,... |
| CVE-2026-48612 | HIGH | 8 | 0.1% | Jun 12, 2026 | Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow an... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now