2026 CVE Vulnerabilities
64,779 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48289 | LOW | 3.5 | 0.3% | Jun 9, 2026 | Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vuln... |
| CVE-2026-48288 | LOW | 3.5 | 0.4% | Jun 9, 2026 | Adobe Experience Manager versions 6.5.24, LTS SP1, 2026.04 and earlier are affected by an Improper Input Validation vuln... |
| CVE-2026-45642 | LOW | 3.9 | 0.3% | Jun 9, 2026 | Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authori... |
| CVE-2026-45485 | LOW | 3.3 | 0.4% | Jun 9, 2026 | Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally. |
| CVE-2026-45466 | LOW | 3.3 | 0.4% | Jun 9, 2026 | Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally. |
| CVE-2026-45459 | LOW | 3.3 | 0.4% | Jun 9, 2026 | Protection mechanism failure in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature loca... |
| CVE-2026-42770 | LOW | 3.7 | 0.3% | Jun 9, 2026 | Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the peer key is not properly check... |
| CVE-2026-42768 | LOW | 3.7 | 0.4% | Jun 9, 2026 | Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to Bleichenbacher-style attack when an attacke... |
| CVE-2026-11792 | LOW | 3.3 | 0.3% | Jun 9, 2026 | A heap buffer overflow flaw was found in 389 Directory Server. When audit logging is enabled, the create_masked_entry_st... |
| CVE-2026-11764 | LOW | 3.6 | 0.2% | Jun 9, 2026 | When creating an export of all reusable media, the secrets of connected gift cards were included in the export even if ... |
| CVE-2026-49738 | LOW | 2.1 | 0.4% | Jun 9, 2026 | The path allowance check in GeneralUtility::isAllowedAbsPath() performed a plain string prefix comparison without requir... |
| CVE-2026-41986 | LOW | 2.4 | 0.1% | Jun 9, 2026 | Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availabi... |
| CVE-2026-41974 | LOW | 3.6 | 0.1% | Jun 9, 2026 | Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may aff... |
| CVE-2026-8981 | LOW | 3.5 | 0.1% | Jun 9, 2026 | The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability acros... |
| CVE-2026-44743 | LOW | 3.7 | 0.2% | Jun 9, 2026 | Under certain conditions, when an unauthorized attacker accesses a specific endpoint, SAP Business Objects application l... |
| CVE-2026-11691 | LOW | 3.1 | 0.2% | Jun 9, 2026 | Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 149.0.7827.103 allowed a remote att... |
| CVE-2026-11686 | LOW | 3.1 | 0.2% | Jun 9, 2026 | Insufficient validation of untrusted input in Dawn in Google Chrome on macOS prior to 149.0.7827.103 allowed a remote at... |
| CVE-2026-11684 | LOW | 3.1 | 0.2% | Jun 9, 2026 | Insufficient policy enforcement in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had co... |
| CVE-2026-11675 | LOW | 3.1 | 0.2% | Jun 9, 2026 | Out of bounds read in Skia in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the re... |
| CVE-2026-47344 | LOW | 2.1 | 0.3% | Jun 8, 2026 | When ALLOW_INSECURE_RAW_TEXT is enabled, whitespace-variant closing tags (e.g., </style\t>) are not recognized by the sa... |
| CVE-2026-11534 | LOW | 3.5 | 0.2% | Jun 8, 2026 | A vulnerability was detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affec... |
| CVE-2026-49756 | LOW | 3.7 | 0.2% | Jun 8, 2026 | Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in wojtekmach Req allows multipart parameter ... |
| CVE-2026-48488 | LOW | 2.7 | 0.2% | Jun 8, 2026 | phpMyFAQ is an open source FAQ web application. Prior to version 4.1.4, attachment passwords are hashed using SHA-1, a c... |
| CVE-2026-11520 | LOW | 3.5 | 0.2% | Jun 8, 2026 | A weakness has been identified in SourceCodester Inventory System 1.0. Affected by this issue is some unknown functional... |
| CVE-2026-11511 | LOW | 3.5 | 0.2% | Jun 8, 2026 | A weakness has been identified in Bolt CMS up to 3.7.5. This vulnerability affects unknown code of the file src/Storage/... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now