2026 CVE Vulnerabilities
48,851 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11456 | HIGH | 7.3 | 0.3% | Jun 7, 2026 | A vulnerability was identified in Chanjet CRM 1.0. This affects an unknown part of the file /tools/jxf_dump_systable.php... |
| CVE-2026-11452 | HIGH | 7.3 | 1.7% | Jun 7, 2026 | A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function FUN_0042e200 of the file /cgi-... |
| CVE-2026-11451 | HIGH | 7.3 | 2.0% | Jun 7, 2026 | A flaw has been found in GL.iNet GL-MT3000 4.4.5. This impacts the function snprintf of the file /cgi-bin/glc of the com... |
| CVE-2026-11450 | HIGH | 7.3 | 1.6% | Jun 7, 2026 | A vulnerability was detected in GL.iNet GL-MT3000 4.4.5. This affects the function dlopen in the library /usr/lib/oui-ht... |
| CVE-2026-26422 | HIGH | 8.4 | 0.2% | Jun 6, 2026 | clash-verge-service-ipc before 2.3.0 has a world-reachable IPC endpoint, leading to local privilege escalation. |
| CVE-2026-11437 | HIGH | 7.3 | 0.4% | Jun 6, 2026 | A flaw has been found in perfree go-fastdfs-web up to 1.3.7. Affected is the function checkServer of the file /install/c... |
| CVE-2026-11435 | HIGH | 7.3 | 0.3% | Jun 6, 2026 | A security vulnerability has been detected in Jinher OA 1.0. This affects an unknown function of the file nextselectplan... |
| CVE-2026-11413 | HIGH | 8.8 | 0.5% | Jun 6, 2026 | A security vulnerability has been detected in JingDong JD Cloud Box AX6600 4.5.3.r4546. The impacted element is the func... |
| CVE-2026-10725 | HIGH | 7.5 | 0.4% | Jun 6, 2026 | Protocol::HTTP2 versions before 1.13 for Perl is vulnerable to a HTTP/2 Bomb. Protocol::HTTP2's inbound HPACK path has ... |
| CVE-2026-9851 | HIGH | 7.2 | 0.3% | Jun 6, 2026 | The Booking Package plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions up to, a... |
| CVE-2026-7537 | HIGH | 7.2 | 0.7% | Jun 6, 2026 | The MDJM Event Management plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and includi... |
| CVE-2026-8901 | HIGH | 7.2 | 0.3% | Jun 6, 2026 | The Integration for Freshsales – Contact Form 7, WPForms, Elementor, Gravity Forms and More plugin for WordPress is vuln... |
| CVE-2026-8438 | HIGH | 7.2 | 0.3% | Jun 6, 2026 | The All-In-One Security (AIOS) – Security and Firewall plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
| CVE-2026-9290 | HIGH | 7.5 | 2.4% | Jun 6, 2026 | The WP User Manager – User Profile Builder & Membership plugin for WordPress is vulnerable to Local File Inclusion in al... |
| CVE-2026-34123 | HIGH | 7 | 0.2% | Jun 6, 2026 | On Tapo C520WS v2, restricted accounts (for example, hub users) are intended to execute only a limited set of low‑sensit... |
| CVE-2026-7654 | HIGH | 8.8 | 0.7% | Jun 5, 2026 | The Admin Columns plugin for WordPress is vulnerable to PHP Object Injection leading to Remote Code Execution in version... |
| CVE-2026-11431 | HIGH | 8.3 | 0.5% | Jun 5, 2026 | A path traversal vulnerability exists in the Projects Service download endpoint shared by Altium Enterprise Server and A... |
| CVE-2026-11424 | HIGH | 8.3 | 0.2% | Jun 5, 2026 | A server-side request forgery (SSRF) vulnerability exists in a GraphQL service component shared by Altium Enterprise Ser... |
| CVE-2026-11416 | HIGH | 8.1 | 0.5% | Jun 5, 2026 | MoviePilot contains a path traversal vulnerability in the AliPan, U115, and Rclone cloud storage download handlers where... |
| CVE-2026-36785 | HIGH | 7.5 | 0.4% | Jun 5, 2026 | Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the page parameter... |
| CVE-2026-11422 | HIGH | 8.4 | 0.2% | Jun 5, 2026 | Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom ren... |
| CVE-2026-46493 | HIGH | 7.5 | 0.3% | Jun 5, 2026 | HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.1 use `uniqid` for generatin... |
| CVE-2026-46400 | HIGH | 8.7 | 0.4% | Jun 5, 2026 | HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 11.0.6 and prior to version 25.... |
| CVE-2026-46398 | HIGH | 8.8 | 0.2% | Jun 5, 2026 | HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 25.0.0 and prior to version 26.... |
| CVE-2026-45300 | HIGH | 7.4 | 0.3% | Jun 5, 2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now