2026 CVE Vulnerabilities
49,638 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45545 | HIGH | 8.2 | 0.3% | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10,... |
| CVE-2026-45302 | HIGH | 8.2 | 0.3% | Jun 1, 2026 | parse-nested-form-data is a tiny node module for parsing FormData by name into objects and arrays. Prior to version 1.0.... |
| CVE-2026-45284 | HIGH | 8.8 | 0.2% | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper chec... |
| CVE-2026-45281 | HIGH | 8.1 | 0.3% | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, a... |
| CVE-2026-43958 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a ... |
| CVE-2026-43625 | HIGH | 8.2 | 0.2% | Jun 1, 2026 | CodexBar prior to 0.32.0 contains a session cookie leakage vulnerability that allows network attackers to intercept impo... |
| CVE-2026-43624 | HIGH | 8.8 | 0.4% | Jun 1, 2026 | F5-TTS through version 1.1.20 contains a path traversal vulnerability in the finetune Gradio handlers that allows unauth... |
| CVE-2026-43623 | HIGH | 8.8 | 0.3% | Jun 1, 2026 | microtar through 0.1.0 contains a stack-based buffer overflow vulnerability in the raw_to_header() function in src/micro... |
| CVE-2026-41013 | HIGH | 8.1 | 0.2% | Jun 1, 2026 | Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF s... |
| CVE-2026-37235 | HIGH | 7.5 | 0.6% | Jun 1, 2026 | FlexRIC v2.0.0 trusts the xapp_id field from E42 message payloads without binding it to the sender's SCTP association. T... |
| CVE-2026-37233 | HIGH | 7.5 | 0.5% | Jun 1, 2026 | FlexRIC v2.0.0 contains an authorization bypass in the iApp's xApp isolation mechanism. The equality function eq_xapp_ri... |
| CVE-2026-37232 | HIGH | 8.6 | 0.4% | Jun 1, 2026 | An issue was discovered in OpenAirInterface5G 2.4.0 (nr-softmodem) in the E2SM-KPM RAN Function's PRB utilization metric... |
| CVE-2026-37231 | HIGH | 7.5 | 0.5% | Jun 1, 2026 | FlexRIC v2.0.0 uses a uint16_t counter for xapp_id assignment but stores the value in uint32_t message fields. After 65,... |
| CVE-2026-37230 | HIGH | 7.5 | 0.6% | Jun 1, 2026 | FlexRIC v2.0.0 crashes when the near-RT RIC receives a RIC_INDICATION message with a ran_func_id that does not exist in ... |
| CVE-2026-37229 | HIGH | 7.5 | 0.6% | Jun 1, 2026 | FlexRIC v2.0.0 contains a reachable assertion in e2ap_create_pdu() triggered when ASN.1 PER decoding fails. A remote una... |
| CVE-2026-37228 | HIGH | 7.5 | 0.6% | Jun 1, 2026 | FlexRIC v2.0.0 contains a reachable assertion in e2ap_recv_sctp_msg() (src/lib/ep/e2ap_ep.c). The function allocates a f... |
| CVE-2026-37226 | HIGH | 7.5 | 0.6% | Jun 1, 2026 | FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST referencing a non-existent E2 Node. The lo... |
| CVE-2026-10281 | HIGH | 7.3 | 0.4% | Jun 1, 2026 | A weakness has been identified in Enderfga claw-orchestrator up to 3.5.5. This affects the function EmbeddedServer of th... |
| CVE-2026-10280 | HIGH | 7.3 | 0.3% | Jun 1, 2026 | A security flaw has been discovered in horizon921 mcpilot 0.1.0. The impacted element is an unknown function of the file... |
| CVE-2026-0072 | HIGH | 7.8 | 0.1% | Jun 1, 2026 | In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission che... |
| CVE-2026-8501 | HIGH | 7.8 | 0.2% | Jun 1, 2026 | Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode proc... |
| CVE-2026-46243 | HIGH | 7.1 | 0.4% | Jun 1, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: client: reject userspace cifs.spnego descripti... |
| CVE-2026-45156 | HIGH | 8.1 | 0.3% | Jun 1, 2026 | Nextcloud is an open source content collaboration platform. From versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, ... |
| CVE-2026-42678 | HIGH | 7.1 | 0.2% | Jun 1, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / Stell... |
| CVE-2026-42677 | HIGH | 7.5 | 0.2% | Jun 1, 2026 | Missing Authorization vulnerability in Ben Balter WP Document Revisions allows Exploiting Incorrectly Configured Access ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now