2026 CVE Vulnerabilities
48,611 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40376 | HIGH | 8.1 | 0.7% | Jun 9, 2026 | Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-40371 | HIGH | 8.8 | 0.6% | Jun 9, 2026 | Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized... |
| CVE-2026-34335 | HIGH | 7 | 0.2% | Jun 9, 2026 | Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca... |
| CVE-2026-34183 | HIGH | 7.5 | 0.5% | Jun 9, 2026 | Issue summary: Remote peer may exhaust heap memory of the QUIC server or client by flooding it with packets containing P... |
| CVE-2026-34181 | HIGH | 7.4 | 0.2% | Jun 9, 2026 | Issue Summary: The PKCS#12 file processing fails to perform sufficient input validation for files that use Password-Base... |
| CVE-2026-34180 | HIGH | 7.5 | 0.5% | Jun 9, 2026 | Issue summary: Parsing a crafted DER-encoded ASN.1 structure with a primitive element whose content exceeds 2 gigabytes ... |
| CVE-2026-33828 | HIGH | 7.8 | 0.3% | Jun 9, 2026 | Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally. |
| CVE-2026-32193 | HIGH | 8.8 | 0.3% | Jun 9, 2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service all... |
| CVE-2026-24181 | HIGH | 7.3 | 0.1% | Jun 9, 2026 | NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A succes... |
| CVE-2026-24180 | HIGH | 7.3 | 0.2% | Jun 9, 2026 | NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A succes... |
| CVE-2026-22926 | HIGH | 7.8 | 0.1% | Jun 9, 2026 | Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability. |
| CVE-2026-0419 | HIGH | 8 | 0.3% | Jun 9, 2026 | Insufficient input validation in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows u... |
| CVE-2026-0411 | HIGH | 8 | 0.3% | Jun 9, 2026 | An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected... |
| CVE-2026-49948 | HIGH | 8.6 | 0.3% | Jun 9, 2026 | Mem0 versions through 0.2.8, fixed in commit ae7f406, contain a missing authorization vulnerability in the self-hosted s... |
| CVE-2026-24065 | HIGH | 8.1 | 0.3% | Jun 9, 2026 | Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability in the privile... |
| CVE-2026-24064 | HIGH | 7.8 | 0.2% | Jun 9, 2026 | Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability. A trusted XPC... |
| CVE-2026-10727 | HIGH | 7.2 | 1.6% | Jun 9, 2026 | An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote aut... |
| CVE-2026-9279 | HIGH | 8.7 | 0.3% | Jun 9, 2026 | Logseq exposes an IPC handler that allows the renderer process to execute shell commands. While an allowlist restricts t... |
| CVE-2026-52907 | HIGH | 7.8 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: media: rockchip: rkcif: fix off by one bugs Change... |
| CVE-2026-52906 | HIGH | 7.7 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: 9p: fix access mode flags being ORed instead of rep... |
| CVE-2026-47899 | HIGH | 8.7 | 0.1% | Jun 9, 2026 | The Electron preload script in Logseq exposes an API method that allows the renderer process to invoke IPC handlers with... |
| CVE-2026-46332 | HIGH | 8 | 0.2% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: greybus: gb-beagleplay: bound bootloader receive bu... |
| CVE-2026-46330 | HIGH | 7.8 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: Revert "net/smc: Introduce TCP ULP support" This r... |
| CVE-2026-46328 | HIGH | 7.3 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix rlimit for posix cpu timers Posix cp... |
| CVE-2026-46327 | HIGH | 7.8 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm: fix unlocked test for dm_suspended_md The func... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now