2026 CVE Vulnerabilities
43,286 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6556 | CRITICAL | 9.1 | 0.3% | Jun 30, 2026 | @fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path argu... |
| CVE-2026-58016 | CRITICAL | 9.1 | 0.5% | Jun 30, 2026 | A flaw was found in GLib. A state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection... |
| CVE-2026-8402 | CRITICAL | 9.8 | — | Jun 30, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electroni... |
| CVE-2026-53690 | CRITICAL | 9.3 | — | Jun 30, 2026 | An SQL Injection vulnerability exists in Redeight CMS version 1.0 via the "userEmail" parameter in the POST "/admin/inde... |
| CVE-2026-14162 | CRITICAL | 9.8 | — | Jun 30, 2026 | Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated... |
| CVE-2026-13766 | CRITICAL | 9.8 | — | Jun 30, 2026 | DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers. The default SQL buil... |
| CVE-2026-9711 | CRITICAL | 9.8 | 0.4% | Jun 30, 2026 | The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the... |
| CVE-2026-12076 | CRITICAL | 9.3 | 0.4% | Jun 30, 2026 | Raytha CMS is vulnerable to SQL Injection within the OData filter parsing pipeline. The vulnerability allows a remote, ... |
| CVE-2026-12819 | CRITICAL | 9.3 | 0.3% | Jun 30, 2026 | Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or access contro... |
| CVE-2026-12818 | CRITICAL | 9.3 | 0.3% | Jun 30, 2026 | Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-... |
| CVE-2026-12073 | CRITICAL | 9.8 | 0.3% | Jun 30, 2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via a... |
| CVE-2026-55276 | CRITICAL | 9.1 | 0.3% | Jun 29, 2026 | Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisa... |
| CVE-2026-53434 | CRITICAL | 9.1 | 0.3% | Jun 29, 2026 | Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connect... |
| CVE-2026-57498 | CRITICAL | 9.6 | 0.2% | Jun 29, 2026 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.... |
| CVE-2026-39868 | CRITICAL | 9.1 | 0.7% | Jun 29, 2026 | This issue was addressed with improved input validation. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Sequ... |
| CVE-2026-37637 | CRITICAL | 9.1 | 0.5% | Jun 29, 2026 | An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php compon... |
| CVE-2026-13763 | CRITICAL | 9.8 | 0.5% | Jun 29, 2026 | Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote ... |
| CVE-2026-13762 | CRITICAL | 9.8 | 0.5% | Jun 29, 2026 | Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to by... |
| CVE-2026-56782 | CRITICAL | 9.8 | 3.0% | Jun 29, 2026 | Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that all... |
| CVE-2026-11720 | CRITICAL | 9.1 | 0.4% | Jun 29, 2026 | A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstr... |
| CVE-2026-13751 | CRITICAL | 9.6 | 0.1% | Jun 29, 2026 | Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request for... |
| CVE-2026-57331 | CRITICAL | 9.9 | — | Jun 29, 2026 | Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions. |
| CVE-2026-56290 | CRITICAL | 9.8 | 18.7% | Jun 29, 2026 | Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension... |
| CVE-2026-49048 | CRITICAL | 9.8 | 0.5% | Jun 28, 2026 | The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenati... |
| CVE-2026-58053 | CRITICAL | 9.9 | 0.3% | Jun 28, 2026 | Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docke... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now