2026 CVE Vulnerabilities
49,638 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10591 | HIGH | 8.8 | 0.4% | Jun 2, 2026 | Insufficient access control restrictions in the file write tool in Amazon Kiro IDE before version 0.11 might allow remot... |
| CVE-2026-10047 | HIGH | 7.8 | 0.1% | Jun 2, 2026 | The Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the real-mode hook handler... |
| CVE-2026-10046 | HIGH | 7.8 | 0.1% | Jun 2, 2026 | Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the BIOS INT 0x15 / E820 memor... |
| CVE-2026-9844 | HIGH | 8.8 | 0.2% | Jun 2, 2026 | Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface mo... |
| CVE-2026-7312 | HIGH | 7.5 | 0.4% | Jun 2, 2026 | CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152... |
| CVE-2026-7201 | HIGH | 8.8 | 0.3% | Jun 2, 2026 | CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441... |
| CVE-2026-7195 | HIGH | 8.1 | 0.5% | Jun 2, 2026 | CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152,... |
| CVE-2026-39555 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Deserialization of Untrusted Data vulnerability in Elated-Themes Askka allows Object Injection. This issue affects Askk... |
| CVE-2026-39553 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-39552 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in... |
| CVE-2026-10622 | HIGH | 8.2 | 0.4% | Jun 2, 2026 | Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to access privileged fun... |
| CVE-2026-10621 | HIGH | 7.5 | 0.4% | Jun 2, 2026 | Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archi... |
| CVE-2026-42685 | HIGH | 7.1 | 0.1% | Jun 2, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ahmad WP Job Porta... |
| CVE-2026-42670 | HIGH | 7.5 | 0.3% | Jun 2, 2026 | Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations allows Exploitin... |
| CVE-2026-42669 | HIGH | 7.5 | 0.2% | Jun 2, 2026 | Missing Authorization vulnerability in EventPrime allows Exploiting Incorrectly Configured Access Control Security Level... |
| CVE-2026-39551 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Deserialization of Untrusted Data vulnerability in Elated-Themes Töbel allows Object Injection. This issue affects Töbe... |
| CVE-2026-39550 | HIGH | 8.1 | 0.3% | Jun 2, 2026 | Deserialization of Untrusted Data vulnerability in Elated-Themes Aperitif allows Object Injection. This issue affects A... |
| CVE-2026-5422 | HIGH | 8.1 | 0.4% | Jun 2, 2026 | A path traversal vulnerability exists in jupyter-server version 2.17.0 due to an incorrect root directory boundary check... |
| CVE-2026-3514 | HIGH | 7.5 | 0.5% | Jun 2, 2026 | In version 3.6.19 of prefecthq/prefect, an authentication bypass vulnerability exists due to the improper handling of UR... |
| CVE-2026-1784 | HIGH | 8.8 | 0.2% | Jun 2, 2026 | The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found... |
| CVE-2026-8293 | HIGH | 7.5 | 0.2% | Jun 2, 2026 | The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its ... |
| CVE-2026-25277 | HIGH | 8.8 | 0.1% | Jun 1, 2026 | Memory corruption while using Strongbox due to buffer overflow. |
| CVE-2026-25276 | HIGH | 8.8 | 0.1% | Jun 1, 2026 | Memory corruption while using Strongbox due to missing bounds check. |
| CVE-2026-25260 | HIGH | 7 | 0.1% | Jun 1, 2026 | Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications. |
| CVE-2026-25259 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | Memory corruption while processing multiple IOCTL command for escape operations. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now