2026 CVE Vulnerabilities
48,557 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46622 | HIGH | 8.1 | 0.2% | Jun 11, 2026 | SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API... |
| CVE-2026-46489 | HIGH | 8.1 | 0.3% | Jun 11, 2026 | SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any ... |
| CVE-2026-45175 | HIGH | 7.8 | 0.1% | Jun 11, 2026 | Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent vali... |
| CVE-2026-52860 | HIGH | 7.8 | 0.2% | Jun 11, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-completion executes recons... |
| CVE-2026-52859 | HIGH | 8.2 | 0.3% | Jun 11, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0565, the update_snapshot() function in src/termin... |
| CVE-2026-52858 | HIGH | 7.8 | 0.2% | Jun 11, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completion script in python3... |
| CVE-2026-48547 | HIGH | 8.5 | 0.9% | Jun 11, 2026 | KanaDojo contains a command injection vulnerability that allows an attacker with pull request access to execute arbitrar... |
| CVE-2026-47189 | HIGH | 8.3 | 0.3% | Jun 11, 2026 | Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.5, the A... |
| CVE-2026-47181 | HIGH | 8.7 | 0.3% | Jun 11, 2026 | PenguinMod-BackendApi is the backend api for penguinmod. Prior to version 1.0.0, a NoSQL injection vulnerability in the ... |
| CVE-2026-47171 | HIGH | 8.8 | 0.3% | Jun 11, 2026 | Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a nor... |
| CVE-2026-47170 | HIGH | 7.7 | 0.2% | Jun 11, 2026 | Garlic-Hub manages digital signage network — devices, content, and playlists — from a single self-hosted interface. Prio... |
| CVE-2026-47169 | HIGH | 7.5 | 0.2% | Jun 11, 2026 | Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, a use... |
| CVE-2026-47163 | HIGH | 7.2 | 0.2% | Jun 11, 2026 | Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.1, any g... |
| CVE-2026-47162 | HIGH | 8.8 | 0.3% | Jun 11, 2026 | Vim is an open source, command line text editor. Prior to version 9.2.0495, a Vimscript code injection vulnerability exi... |
| CVE-2026-46519 | HIGH | 8.8 | 0.4% | Jun 11, 2026 | mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.6.0, mcp-... |
| CVE-2026-45178 | HIGH | 8.1 | 0.4% | Jun 11, 2026 | Idira Secrets Manager Self-Hosted versions 13.8.0 and lower exhibit improper access control within internal cluster endp... |
| CVE-2026-45176 | HIGH | 7.8 | 0.1% | Jun 11, 2026 | Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged age... |
| CVE-2026-11774 | HIGH | 7.6 | 0.7% | Jun 11, 2026 | An integer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). In sasl_io_start_packet(... |
| CVE-2026-48546 | HIGH | 8.5 | 0.5% | Jun 11, 2026 | KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by expl... |
| CVE-2026-46697 | HIGH | 7.5 | 0.2% | Jun 11, 2026 | Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unaut... |
| CVE-2026-3329 | HIGH | 7.5 | 0.5% | Jun 11, 2026 | A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype N... |
| CVE-2026-49982 | HIGH | 8.2 | 0.5% | Jun 11, 2026 | tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects ... |
| CVE-2026-44705 | HIGH | 8.2 | 0.4% | Jun 11, 2026 | tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal... |
| CVE-2026-44496 | HIGH | 7.5 | 0.6% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and befor... |
| CVE-2026-44495 | HIGH | 7.7 | 0.8% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contain... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now