2026 CVE Vulnerabilities
48,557 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46654 | HIGH | 8.9 | 0.1% | Jun 10, 2026 | Plonky3 is a toolkit for polynomial IOPs (PIOPs). Prior to versions 0.4.3 and 0.5.3, an attacker controlling prover-side... |
| CVE-2026-46625 | HIGH | 7.5 | 0.5% | Jun 10, 2026 | JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal as... |
| CVE-2026-46522 | HIGH | 7.5 | 1.8% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.2... |
| CVE-2026-46520 | HIGH | 7.5 | 0.4% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-45783 | HIGH | 7.5 | 0.4% | Jun 10, 2026 | libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 16.2.6, an unauthenticated remote pee... |
| CVE-2026-44692 | HIGH | 7.7 | 0.3% | Jun 10, 2026 | Sharp is a content management framework built for Laravel as a package. Prior to version 9.22.0, Sharp exposes a generic... |
| CVE-2026-42542 | HIGH | 7.5 | 0.5% | Jun 10, 2026 | TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3... |
| CVE-2026-42462 | HIGH | 7 | 0.2% | Jun 10, 2026 | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10... |
| CVE-2026-2049 | HIGH | 7.8 | 0.6% | Jun 10, 2026 | GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a... |
| CVE-2026-10143 | HIGH | 7.5 | 0.5% | Jun 10, 2026 | kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handling that allows a ma... |
| CVE-2026-10142 | HIGH | 8.7 | 0.3% | Jun 10, 2026 | kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious br... |
| CVE-2026-0273 | HIGH | 7.2 | 1.4% | Jun 10, 2026 | A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypas... |
| CVE-2026-0272 | HIGH | 7.2 | 0.3% | Jun 10, 2026 | A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with a... |
| CVE-2026-0271 | HIGH | 7.8 | 0.1% | Jun 10, 2026 | A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a l... |
| CVE-2026-0270 | HIGH | 7.5 | 0.2% | Jun 10, 2026 | A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenti... |
| CVE-2026-6893 | HIGH | 7.5 | 1.1% | Jun 10, 2026 | A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specia... |
| CVE-2026-46643 | HIGH | 7.5 | 0.2% | Jun 10, 2026 | Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.1... |
| CVE-2026-46529 | HIGH | 8.4 | 0.5% | Jun 10, 2026 | Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote co... |
| CVE-2026-1220 | HIGH | 7.5 | 0.3% | Jun 10, 2026 | Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a... |
| CVE-2026-50637 | HIGH | 8.2 | 0.3% | Jun 10, 2026 | Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections. The statsd prot... |
| CVE-2026-9151 | HIGH | 8.5 | 1.1% | Jun 10, 2026 | An OS command injection vulnerability exists in the VPN module of TP-Link Archer AX12 v1, AX17 v1. AX18 v1, and AX1300 v... |
| CVE-2026-50570 | HIGH | 8.5 | 0.3% | Jun 10, 2026 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic... |
| CVE-2026-50567 | HIGH | 7.7 | 0.3% | Jun 10, 2026 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic... |
| CVE-2026-49824 | HIGH | 8.5 | 0.2% | Jun 10, 2026 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic... |
| CVE-2026-49823 | HIGH | 7.7 | 0.3% | Jun 10, 2026 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now