2026 CVE Vulnerabilities
49,059 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48681 | HIGH | 8.1 | 0.6% | Jun 4, 2026 | OpenStack Ironic through before 35.0.2 allows file overwrite via directory traversal during deployment with a crafted IS... |
| CVE-2026-41010 | HIGH | 8.7 | 0.1% | Jun 4, 2026 | ReleaseJob#unpack builds job_dir = File.join(@release_dir, 'jobs', name) and job_tgz = File.join(@release_dir, 'jobs', "... |
| CVE-2026-8829 | HIGH | 7.5 | 0.3% | Jun 4, 2026 | HTML::Entities versions before 3.84 for Perl read freed heap memory in _decode_entities. The XS routine backing HTML::E... |
| CVE-2026-41860 | HIGH | 8.8 | 0.1% | Jun 4, 2026 | CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpReq... |
| CVE-2026-41859 | HIGH | 7.8 | 0.1% | Jun 4, 2026 | A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth heade... |
| CVE-2026-41858 | HIGH | 7.5 | 0.2% | Jun 4, 2026 | Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem / windows-utilities... |
| CVE-2026-41011 | HIGH | 8.7 | 0.1% | Jun 4, 2026 | PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz")... |
| CVE-2026-10737 | HIGH | 7.5 | 0.3% | Jun 4, 2026 | The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability ... |
| CVE-2026-10777 | HIGH | 7.3 | 0.4% | Jun 3, 2026 | A vulnerability was identified in ealpha072 Student-Management-System up to 01451bd7a2f58cdda07bd0b86e3967582e3ecd08. Af... |
| CVE-2026-46447 | HIGH | 7.7 | 0.3% | Jun 3, 2026 | OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info o... |
| CVE-2026-22055 | HIGH | 8.8 | 0.2% | Jun 3, 2026 | Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low p... |
| CVE-2026-22054 | HIGH | 8.8 | 0.2% | Jun 3, 2026 | Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with l... |
| CVE-2026-10771 | HIGH | 7.3 | 0.3% | Jun 3, 2026 | A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-... |
| CVE-2026-50033 | HIGH | 7.3 | 0.1% | Jun 3, 2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock D... |
| CVE-2026-44682 | HIGH | 7.3 | 0.1% | Jun 3, 2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock D... |
| CVE-2026-44609 | HIGH | 7.3 | 0.1% | Jun 3, 2026 | Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock D... |
| CVE-2026-42061 | HIGH | 7.3 | 0.1% | Jun 3, 2026 | Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected... |
| CVE-2026-8889 | HIGH | 7.5 | 0.2% | Jun 3, 2026 | Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) an... |
| CVE-2026-8888 | HIGH | 7.5 | 0.4% | Jun 3, 2026 | Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as J... |
| CVE-2026-8881 | HIGH | 7.5 | 0.2% | Jun 3, 2026 | Version 3.0.7 of the Securly Chrome Extension uses EVP_BytesToKey key derivation with MD5 and a single iteration for AES... |
| CVE-2026-8879 | HIGH | 7.5 | 0.4% | Jun 3, 2026 | Version 3.0.7 of the Securly Chrome Extension dynamically registers content13.min.js as a content script via chrome.scri... |
| CVE-2026-8878 | HIGH | 7.5 | 0.2% | Jun 3, 2026 | Version 3.0.7 of the Securly Chrome Extension exposes multiple publicly accessible endpoints that allow unauthenticated ... |
| CVE-2026-8876 | HIGH | 7.3 | 0.2% | Jun 3, 2026 | Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in securly.min.js. These key... |
| CVE-2026-8874 | HIGH | 7.1 | 0.1% | Jun 3, 2026 | Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules ... |
| CVE-2026-7888 | HIGH | 8.4 | 0.2% | Jun 3, 2026 | Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now