2026 CVE Vulnerabilities
43,286 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12415 | CRITICAL | 9.8 | 0.7% | Jun 27, 2026 | The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on th... |
| CVE-2026-31928 | CRITICAL | 9.8 | 0.4% | Jun 26, 2026 | The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are ... |
| CVE-2026-53576 | CRITICAL | 10 | 0.5% | Jun 26, 2026 | Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for... |
| CVE-2026-49869 | CRITICAL | 10 | 0.7% | Jun 26, 2026 | Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestr... |
| CVE-2026-54352 | CRITICAL | 9.6 | 0.5% | Jun 26, 2026 | Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/ro... |
| CVE-2026-54351 | CRITICAL | 9.6 | 0.4% | Jun 26, 2026 | Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly acce... |
| CVE-2026-54350 | CRITICAL | 9.8 | 0.4% | Jun 26, 2026 | Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase ap... |
| CVE-2026-50137 | CRITICAL | 9.4 | 0.3% | Jun 26, 2026 | Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or can enumerate a worksp... |
| CVE-2026-53309 | CRITICAL | 9.8 | 0.4% | Jun 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: fix off-by-one in dlm_match_regions() re... |
| CVE-2026-52785 | CRITICAL | 9.9 | 0.2% | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection ... |
| CVE-2026-52782 | CRITICAL | 9.9 | 0.3% | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through ... |
| CVE-2026-52780 | CRITICAL | 9.6 | — | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, cache store poisoning lea... |
| CVE-2026-46386 | CRITICAL | 9.9 | 0.3% | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docke... |
| CVE-2026-33646 | CRITICAL | 9.6 | 0.7% | Jun 26, 2026 | mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files ... |
| CVE-2026-54636 | CRITICAL | 9.9 | 0.3% | Jun 26, 2026 | Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system... |
| CVE-2026-45408 | CRITICAL | 9 | — | Jun 26, 2026 | Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell meta... |
| CVE-2026-12411 | CRITICAL | 9.6 | 0.1% | Jun 26, 2026 | Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, r... |
| CVE-2026-0685 | CRITICAL | 9.8 | — | Jun 26, 2026 | Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows... |
| CVE-2026-57658 | CRITICAL | 9.1 | — | Jun 26, 2026 | Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions. |
| CVE-2026-56070 | CRITICAL | 9.3 | — | Jun 26, 2026 | Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions. |
| CVE-2026-56068 | CRITICAL | 9.3 | 0.2% | Jun 26, 2026 | Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions. |
| CVE-2026-56067 | CRITICAL | 9.3 | — | Jun 26, 2026 | Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions. |
| CVE-2026-56062 | CRITICAL | 9.3 | — | Jun 26, 2026 | Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions. |
| CVE-2026-56059 | CRITICAL | 9.9 | — | Jun 26, 2026 | Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions. |
| CVE-2026-56058 | CRITICAL | 9.9 | — | Jun 26, 2026 | Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now