2026 CVE Vulnerabilities
64,779 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9062 | LOW | 3.4 | 0.2% | Jun 13, 2026 | The Store Locator WordPress plugin before 1.6.9 does not validate a parameter before using it in a file path, allowing h... |
| CVE-2026-9061 | LOW | 3.5 | 0.1% | Jun 13, 2026 | The Store Locator WordPress plugin before 1.6.9 does not sanitize and escape store logo metadata before storing it and o... |
| CVE-2026-53607 | LOW | 3.7 | 0.2% | Jun 12, 2026 | ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, when `prettyU... |
| CVE-2026-12130 | LOW | 3.5 | 0.2% | Jun 12, 2026 | A security flaw has been discovered in CodeAstro Human Resource Management System 1.0. This affects an unknown part of t... |
| CVE-2026-12129 | LOW | 3.5 | 0.2% | Jun 12, 2026 | A vulnerability was identified in CodeAstro Human Resource Management System 1.0. Affected by this issue is some unknown... |
| CVE-2026-53724 | LOW | 2.1 | 0.3% | Jun 12, 2026 | Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version... |
| CVE-2026-12065 | LOW | 1.8 | 0.1% | Jun 12, 2026 | A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This affects an unknown ... |
| CVE-2026-48485 | LOW | 2.1 | 0.3% | Jun 12, 2026 | Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the latest release suppresses mentions when creating, un... |
| CVE-2026-9269 | LOW | 3.5 | 0.1% | Jun 12, 2026 | The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some o... |
| CVE-2026-12032 | LOW | 3.1 | 0.2% | Jun 11, 2026 | Inappropriate implementation in Passwords in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker ... |
| CVE-2026-12017 | LOW | 3.1 | 0.2% | Jun 11, 2026 | Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had co... |
| CVE-2026-47188 | LOW | 2.3 | 0.2% | Jun 11, 2026 | Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.5, the l... |
| CVE-2026-47175 | LOW | 2.3 | 0.2% | Jun 11, 2026 | Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, sever... |
| CVE-2026-6976 | LOW | 3.7 | 0.2% | Jun 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, an... |
| CVE-2026-3553 | LOW | 3.1 | 0.2% | Jun 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, an... |
| CVE-2026-41000 | LOW | 3.7 | 0.2% | Jun 11, 2026 | Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-ti... |
| CVE-2026-47712 | LOW | 3.3 | 0.1% | Jun 10, 2026 | Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to v... |
| CVE-2026-48011 | LOW | 3.7 | 0.2% | Jun 10, 2026 | Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the us... |
| CVE-2026-46668 | LOW | 2.3 | 0.3% | Jun 10, 2026 | SpiceDB is an open source database system for creating and managing security-critical application permissions. From vers... |
| CVE-2026-45380 | LOW | 3.6 | 0.1% | Jun 10, 2026 | bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4... |
| CVE-2026-50568 | LOW | 3.6 | 0.1% | Jun 10, 2026 | Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic... |
| CVE-2026-46497 | LOW | 2.3 | 0.3% | Jun 10, 2026 | Crawlee is a web scraping and browser automation library. From version 1.0.0 to before version 1.7.0, Crawlee is vulnera... |
| CVE-2026-11859 | LOW | 2 | 0.3% | Jun 10, 2026 | An HTML injection vulnerability in the "fetch links" email sent by Thinkst Applied Research Canarytokens, enabling Inter... |
| CVE-2026-9060 | LOW | 3.5 | 0.1% | Jun 10, 2026 | The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and o... |
| CVE-2026-29114 | LOW | 2.3 | 0.2% | Jun 10, 2026 | A vulnerability has been found in some Dahua products. An attacker may obtain the device’s CA root certificate. If that ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now