2026 CVE Vulnerabilities
49,581 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47201 | HIGH | 8.5 | 0.2% | Jun 2, 2026 | authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Sou... |
| CVE-2026-10620 | HIGH | 7.3 | 0.3% | Jun 2, 2026 | A flaw has been found in code-projects Student Admission System 1.0. Affected is an unknown function of the file /index.... |
| CVE-2026-10619 | HIGH | 7.3 | 0.5% | Jun 2, 2026 | A vulnerability was detected in sayan365 student-management-system up to 7f3c9ce7d410332335c2affac93a385485051800. This ... |
| CVE-2026-8036 | HIGH | 7.8 | 0.1% | Jun 2, 2026 | Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially ... |
| CVE-2026-5385 | HIGH | 8.4 | 0.4% | Jun 2, 2026 | An unauthenticated user with write access to the knowledge base can store an XSS payload in a knowledge base item. Thi... |
| CVE-2026-5073 | HIGH | 7.5 | 1.4% | Jun 2, 2026 | The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'arm_directory... |
| CVE-2026-49120 | HIGH | 8.5 | 0.2% | Jun 2, 2026 | Medplum before 5.1.14 contains a server-side request forgery vulnerability in the subscription worker that allows authen... |
| CVE-2026-48594 | HIGH | 7.5 | 0.3% | Jun 2, 2026 | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-tesla tesla allows a denial of ... |
| CVE-2026-47265 | HIGH | 7.5 | 0.1% | Jun 2, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set wit... |
| CVE-2026-42342 | HIGH | 7.5 | 0.3% | Jun 2, 2026 | React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 ... |
| CVE-2026-42211 | HIGH | 8.1 | 0.4% | Jun 2, 2026 | React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps ... |
| CVE-2026-41577 | HIGH | 7.5 | 0.2% | Jun 2, 2026 | authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response proces... |
| CVE-2026-34993 | HIGH | 7.3 | 0.2% | Jun 2, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJ... |
| CVE-2026-34077 | HIGH | 7.5 | 0.3% | Jun 2, 2026 | React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Co... |
| CVE-2026-28299 | HIGH | 7.5 | 0.4% | Jun 2, 2026 | SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause... |
| CVE-2026-1829 | HIGH | 8.8 | 0.7% | Jun 2, 2026 | The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up t... |
| CVE-2026-10701 | HIGH | 7.5 | 0.3% | Jun 2, 2026 | Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 151.0.3. |
| CVE-2026-10617 | HIGH | 7.3 | 0.4% | Jun 2, 2026 | A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. This affects the function resolveAut... |
| CVE-2026-10608 | HIGH | 7.3 | 0.3% | Jun 2, 2026 | A security flaw has been discovered in DedeCMS 5.7.88. This affects the function RemoveXSS of the file /plus/carbuyactio... |
| CVE-2026-10607 | HIGH | 7.3 | 0.3% | Jun 2, 2026 | A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function dede_htmlspecialchars of the file... |
| CVE-2026-10584 | HIGH | 8.2 | 0.1% | Jun 2, 2026 | Proxy server in Graph Explorer before 3.0.1 falls back to HTTP when certificate files are missing, which might allow rem... |
| CVE-2026-40715 | HIGH | 7.8 | 0.1% | Jun 2, 2026 | Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privile... |
| CVE-2026-24237 | HIGH | 7.8 | 0.2% | Jun 2, 2026 | NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A su... |
| CVE-2026-24221 | HIGH | 7.8 | 0.2% | Jun 2, 2026 | NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A su... |
| CVE-2026-10606 | HIGH | 7.3 | 0.3% | Jun 2, 2026 | A vulnerability was determined in DedeCMS 5.7.88. The affected element is the function TrimMsg of the file /plus/feedbac... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now