2026 CVE Vulnerabilities
49,055 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-38570 | HIGH | 7.5 | 0.3% | Jun 4, 2026 | bacnet_stack 1.3.1 contains an Out-of-bounds Read in bacnet_tag_number_decode which allows attackers to cause a denial o... |
| CVE-2026-10814 | HIGH | 7 | 0.1% | Jun 4, 2026 | A vulnerability has been found in milvus-io milvus up to 2.6.13. This vulnerability affects unknown code of the file int... |
| CVE-2026-41065 | HIGH | 8.9 | 0.4% | Jun 4, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 are vulnerable t... |
| CVE-2026-36176 | HIGH | 7.1 | 0.1% | Jun 4, 2026 | GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial c... |
| CVE-2026-28318 | HIGH | 7.5 | 10.7% | Jun 4, 2026 | SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication... |
| CVE-2026-10863 | HIGH | 8.1 | 0.2% | Jun 4, 2026 | A security issue was fixed in the correlations over-correlation endpoint where the order query parameter was accepted fr... |
| CVE-2026-45433 | HIGH | 8.7 | 0.3% | Jun 4, 2026 | This vulnerability exists in GX Earth 2022 ONT models due to the presence of hardcoded RSA private key within the device... |
| CVE-2026-45432 | HIGH | 8.7 | 0.2% | Jun 4, 2026 | This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plaintext over HTTP in i... |
| CVE-2026-45431 | HIGH | 8.7 | 0.4% | Jun 4, 2026 | This vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic ... |
| CVE-2026-10843 | HIGH | 7.2 | 0.3% | Jun 4, 2026 | A flaw was found in the OpenShift Cloud Credential Operator Mint-mode IAM policies for AWS. Operator credentials are pro... |
| CVE-2026-10840 | HIGH | 7.1 | 0.2% | Jun 4, 2026 | A flaw was found in the OpenShift Pipelines operator. The tekton-scheduler-rolebinding ClusterRoleBinding grants the sys... |
| CVE-2026-49771 | HIGH | 7.6 | 0.2% | Jun 4, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in 10Web Photo Galler... |
| CVE-2026-50213 | HIGH | 7.5 | 0.2% | Jun 4, 2026 | The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled b... |
| CVE-2026-50210 | HIGH | 7.5 | 0.2% | Jun 4, 2026 | The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to re... |
| CVE-2026-50209 | HIGH | 7.8 | 0.1% | Jun 4, 2026 | Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint addres... |
| CVE-2026-50207 | HIGH | 7.8 | 0.1% | Jun 4, 2026 | The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read base... |
| CVE-2026-3820 | HIGH | 7.2 | 0.4% | Jun 4, 2026 | There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR. An attacker may obtain admini... |
| CVE-2026-50205 | HIGH | 8.2 | 0.2% | Jun 4, 2026 | System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identifi... |
| CVE-2026-49203 | HIGH | 8.3 | 0.2% | Jun 4, 2026 | Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote prof... |
| CVE-2026-49202 | HIGH | 8.6 | 0.3% | Jun 4, 2026 | Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource S... |
| CVE-2026-49194 | HIGH | 8.8 | 0.2% | Jun 4, 2026 | The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and dire... |
| CVE-2026-49193 | HIGH | 7.5 | 0.2% | Jun 4, 2026 | Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the... |
| CVE-2026-49190 | HIGH | 8.8 | 0.4% | Jun 4, 2026 | The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unau... |
| CVE-2026-49189 | HIGH | 7.8 | 0.1% | Jun 4, 2026 | Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke ... |
| CVE-2026-49187 | HIGH | 7.5 | 0.2% | Jun 4, 2026 | The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now