2026 CVE Vulnerabilities
48,877 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-50260 | HIGH | 7.8 | 0.2% | Jun 5, 2026 | A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple Sync... |
| CVE-2026-50259 | HIGH | 7.8 | 0.2% | Jun 5, 2026 | A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-siz... |
| CVE-2026-50258 | HIGH | 7.8 | 0.2% | Jun 5, 2026 | A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers... |
| CVE-2026-50257 | HIGH | 7.8 | 0.1% | Jun 5, 2026 | A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multip... |
| CVE-2026-50256 | HIGH | 7.8 | 0.2% | Jun 5, 2026 | A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the... |
| CVE-2026-8914 | HIGH | 8.4 | 0.5% | Jun 5, 2026 | In Teltonika Networks RUTOS devices, running versions 7.22 through 7.23.2 and TSWOS devices running versions 1.09 throug... |
| CVE-2026-21037 | HIGH | 7.1 | 0.1% | Jun 5, 2026 | Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL an... |
| CVE-2026-21035 | HIGH | 7.5 | 0.3% | Jun 5, 2026 | Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive infor... |
| CVE-2026-21033 | HIGH | 7.1 | 0.1% | Jun 5, 2026 | Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3... |
| CVE-2026-21032 | HIGH | 7.1 | 0.1% | Jun 5, 2026 | Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.1... |
| CVE-2026-21031 | HIGH | 7.8 | 0.1% | Jun 5, 2026 | Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. U... |
| CVE-2026-21030 | HIGH | 7.8 | 0.1% | Jun 5, 2026 | Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileg... |
| CVE-2026-21029 | HIGH | 7.8 | 0.1% | Jun 5, 2026 | Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local... |
| CVE-2026-11347 | HIGH | 8.5 | 0.1% | Jun 5, 2026 | The linqi application contains hardcoded cryptographic keys. Additionally, the application uses a weak algorithm with a ... |
| CVE-2026-11332 | HIGH | 7.8 | 0.2% | Jun 5, 2026 | A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a rol... |
| CVE-2026-21837 | HIGH | 8.8 | 0.9% | Jun 5, 2026 | HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API. An att... |
| CVE-2026-50593 | HIGH | 7.3 | 0.1% | Jun 5, 2026 | Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat d... |
| CVE-2026-41567 | HIGH | 7.2 | 0.2% | Jun 5, 2026 | Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, whe... |
| CVE-2026-50589 | HIGH | 7.5 | 0.4% | Jun 5, 2026 | In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpo... |
| CVE-2026-11307 | HIGH | 8.8 | 0.2% | Jun 5, 2026 | Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-11306 | HIGH | 8.8 | 0.2% | Jun 5, 2026 | Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-11305 | HIGH | 8.8 | 0.2% | Jun 5, 2026 | Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-11304 | HIGH | 8.8 | 0.2% | Jun 5, 2026 | Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap c... |
| CVE-2026-11303 | HIGH | 8.8 | 0.2% | Jun 5, 2026 | Use after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-11301 | HIGH | 8.8 | 0.2% | Jun 5, 2026 | Inappropriate implementation in LiveCaption in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potenti... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now