2026 CVE Vulnerabilities
48,614 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46327 | HIGH | 7.8 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: dm: fix unlocked test for dm_suspended_md The func... |
| CVE-2026-46326 | HIGH | 8.4 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: iio: pressure: mprls0025pa: fix spi_transfer struct... |
| CVE-2026-11788 | HIGH | 7.5 | 0.6% | Jun 9, 2026 | A flaw was found in 389 Directory Server. The dereference control plugin does not check for allocation failure before us... |
| CVE-2026-46324 | HIGH | 7.8 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: use list_del_rcu for netlink ... |
| CVE-2026-46323 | HIGH | 7.8 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: gro: don't merge zcopy skbs skb_gro_receive()... |
| CVE-2026-46322 | HIGH | 7.1 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: tun: free page on build_skb failure in tun_xdp_one(... |
| CVE-2026-46321 | HIGH | 7.1 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: tun: free page on short-frame rejection in tun_xdp_... |
| CVE-2026-46320 | HIGH | 7.4 | 0.2% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: tap: free page on error paths in tap_get_user_xdp()... |
| CVE-2026-46319 | HIGH | 7.8 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: net/sched: act_ct: Only release RCU read lock after... |
| CVE-2026-46317 | HIGH | 8.8 | 0.1% | Jun 9, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Reassign nested_mmus array behind mmu_l... |
| CVE-2026-2638 | HIGH | 7.3 | 0.1% | Jun 9, 2026 | A vulnerability in the quarantine and restore workflow of the X-VPN macOS website versions 77.0 through 77.5 allow a loc... |
| CVE-2026-49742 | HIGH | 7.1 | 0.3% | Jun 9, 2026 | Backend users with file download permissions were able to download files from the fallback storage of the file abstracti... |
| CVE-2026-49741 | HIGH | 8.7 | 0.2% | Jun 9, 2026 | Backend users with write access to the form_definition database table were able to directly create, update, or delete fo... |
| CVE-2026-47346 | HIGH | 7.6 | 0.3% | Jun 9, 2026 | Backend users with file write permissions were able to upload form definition files with mixed-case extensions (e.g., .F... |
| CVE-2026-47343 | HIGH | 7.2 | 0.2% | Jun 9, 2026 | Non-privileged backend users with file mount access were able to perform write operations (move, delete, rename) on fold... |
| CVE-2026-11607 | HIGH | 7.6 | 0.2% | Jun 9, 2026 | Backend users with access to the Form Framework were able to use files not ending in .form.yaml as form definitions, whi... |
| CVE-2026-46748 | HIGH | 7.8 | 0.2% | Jun 9, 2026 | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The affected system includes a bina... |
| CVE-2026-46746 | HIGH | 8.8 | 0.5% | Jun 9, 2026 | A vulnerability has been identified in SINEC INS (All versions < V1.0 SP2 Update 6). The application does not properly s... |
| CVE-2026-24349 | HIGH | 8.2 | 0.1% | Jun 9, 2026 | A vulnerability has been identified in SIMATIC WinCC Unified PC Runtime V16 (All versions), SIMATIC WinCC Unified PC Run... |
| CVE-2026-8365 | HIGH | 8.8 | 0.8% | Jun 9, 2026 | The Blocksy theme for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution via the 'blocksy_... |
| CVE-2026-11616 | HIGH | 8.8 | 0.3% | Jun 9, 2026 | The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in versions up to and in... |
| CVE-2026-5068 | HIGH | 8.8 | 0.5% | Jun 9, 2026 | A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host during L2CAP LE CoC SD... |
| CVE-2026-11572 | HIGH | 8.8 | 1.1% | Jun 9, 2026 | Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to impro... |
| CVE-2026-9662 | HIGH | 8.1 | 0.6% | Jun 9, 2026 | The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and in... |
| CVE-2026-9185 | HIGH | 7.5 | 0.4% | Jun 9, 2026 | The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now