2026 CVE Vulnerabilities
49,638 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0091 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In multiple locations, there is a possible way to execute code in the launcher process due to an over-privileged shell u... |
| CVE-2026-0089 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In multiple functions of PackageInstallerService.java, there is a possible way to install unverified apps due to a missi... |
| CVE-2026-0088 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In getCallingAppLabel of CertInstaller.java, there is a possible way to hide a sensitive security dialogue due to mislea... |
| CVE-2026-0087 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app ... |
| CVE-2026-0078 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due to improper input va... |
| CVE-2026-0077 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In resumeConfigurationDispatch of ActivityRecord.java, there is a possible background application launch (bal) due to a ... |
| CVE-2026-0076 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In validateNode of ResourceTypes.cpp, there is a possible out of bounds read due to an incorrect bounds check. This coul... |
| CVE-2026-0059 | HIGH | 8 | 0.1% | Jun 1, 2026 | In multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to a heap buffer overfl... |
| CVE-2026-0045 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In bta_jv_rfcomm_connect of bta_jv_act.cc, there is a possible bypass of bonding for a secure connection due to a logic ... |
| CVE-2026-0036 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In startAnimation of StageCoordinator.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. Thi... |
| CVE-2026-0009 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In multiple locations, there is a possible tapjacking due to a logic error in the code. This could lead to local escalat... |
| CVE-2026-49139 | HIGH | 7 | 0.4% | Jun 1, 2026 | Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handl... |
| CVE-2026-49136 | HIGH | 8.7 | 0.4% | Jun 1, 2026 | Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversal vulnerability in the generate_image() ... |
| CVE-2026-49135 | HIGH | 7.2 | 0.1% | Jun 1, 2026 | CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to acces... |
| CVE-2026-49134 | HIGH | 7.5 | 0.3% | Jun 1, 2026 | CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CLI installer that allows local attackers ... |
| CVE-2026-37234 | HIGH | 8.2 | 0.3% | Jun 1, 2026 | FlexRIC v2.0.0 allows a single SCTP connection to bind multiple xapp_ids by sending multiple E42_SETUP_REQUESTs. On disc... |
| CVE-2026-24751 | HIGH | 8.2 | 0.3% | Jun 1, 2026 | Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Dat... |
| CVE-2026-10288 | HIGH | 7.3 | 0.5% | Jun 1, 2026 | A vulnerability was identified in code-projects Hotel and Tourism Reservation System 1.0. This issue affects the functio... |
| CVE-2026-10287 | HIGH | 7.3 | 0.3% | Jun 1, 2026 | A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. This vulnerability affects the function get... |
| CVE-2026-9614 | HIGH | 8.8 | 1.4% | Jun 1, 2026 | An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticate... |
| CVE-2026-9330 | HIGH | 8.5 | 0.5% | Jun 1, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deseria... |
| CVE-2026-7770 | HIGH | 8.8 | 0.4% | Jun 1, 2026 | IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution ... |
| CVE-2026-47294 | HIGH | 8 | 0.6% | Jun 1, 2026 | Improper neutralization of special elements used in an os command ('os command injection') in Microsoft Office SharePoin... |
| CVE-2026-45727 | HIGH | 8.8 | 0.5% | Jun 1, 2026 | CloakBrowser is a tool to bypass bot detection tests. Prior to version 0.3.28, the cloakserve CDP multiplexer uses the u... |
| CVE-2026-45722 | HIGH | 7.1 | 0.3% | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and 1.0.0 to before 1.0... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now