2026 CVE Vulnerabilities
49,206 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-35080 | HIGH | 8.1 | 0.4% | Jun 3, 2026 | The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insuffic... |
| CVE-2026-35079 | HIGH | 8.1 | 0.4% | Jun 3, 2026 | The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient... |
| CVE-2026-35078 | HIGH | 8.1 | 0.4% | Jun 3, 2026 | The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficien... |
| CVE-2026-35077 | HIGH | 8.1 | 0.4% | Jun 3, 2026 | The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insuffi... |
| CVE-2026-35076 | HIGH | 8.1 | 0.4% | Jun 3, 2026 | The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insuffici... |
| CVE-2026-41032 | HIGH | 7.5 | 0.3% | Jun 3, 2026 | It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some... |
| CVE-2026-4035 | HIGH | 7.7 | 0.4% | Jun 3, 2026 | A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gatew... |
| CVE-2026-50031 | HIGH | 7.5 | 0.4% | Jun 3, 2026 | ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Manag... |
| CVE-2026-10704 | HIGH | 7.3 | 0.3% | Jun 3, 2026 | A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the func... |
| CVE-2026-9516 | HIGH | 7.5 | 0.4% | Jun 3, 2026 | Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter... |
| CVE-2026-9334 | HIGH | 7.3 | 0.3% | Jun 3, 2026 | Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref i... |
| CVE-2026-10694 | HIGH | 7.3 | 0.3% | Jun 3, 2026 | A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function i... |
| CVE-2026-44654 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, a sha... |
| CVE-2026-42504 | HIGH | 7.5 | 0.6% | Jun 2, 2026 | Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU. |
| CVE-2026-40108 | HIGH | 7.1 | 0.3% | Jun 2, 2026 | GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XS... |
| CVE-2026-31942 | HIGH | 7.1 | 0.2% | Jun 2, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.7.6, an In... |
| CVE-2026-25861 | HIGH | 8.2 | 0.2% | Jun 2, 2026 | QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attack... |
| CVE-2026-8936 | HIGH | 8.2 | 0.1% | Jun 2, 2026 | Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container created deeply nested dire... |
| CVE-2026-49443 | HIGH | 8.8 | 0.3% | Jun 2, 2026 | authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the... |
| CVE-2026-49144 | HIGH | 7.1 | 0.2% | Jun 2, 2026 | BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js ... |
| CVE-2026-49143 | HIGH | 8.8 | 0.4% | Jun 2, 2026 | BrowserStack Runner through 0.9.5 contains a remote code execution vulnerability in the /_log HTTP handler that allows u... |
| CVE-2026-47201 | HIGH | 8.5 | 0.2% | Jun 2, 2026 | authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Sou... |
| CVE-2026-10620 | HIGH | 7.3 | 0.3% | Jun 2, 2026 | A flaw has been found in code-projects Student Admission System 1.0. Affected is an unknown function of the file /index.... |
| CVE-2026-10619 | HIGH | 7.3 | 0.5% | Jun 2, 2026 | A vulnerability was detected in sayan365 student-management-system up to 7f3c9ce7d410332335c2affac93a385485051800. This ... |
| CVE-2026-8036 | HIGH | 7.8 | 0.1% | Jun 2, 2026 | Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now