2026 CVE Vulnerabilities
43,286 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56057 | CRITICAL | 9.8 | — | Jun 26, 2026 | Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions. |
| CVE-2026-56036 | CRITICAL | 9.3 | — | Jun 26, 2026 | Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions. |
| CVE-2026-56034 | CRITICAL | 9.3 | 0.3% | Jun 26, 2026 | Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions. |
| CVE-2026-56033 | CRITICAL | 9.8 | — | Jun 26, 2026 | Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions. |
| CVE-2026-56032 | CRITICAL | 9.8 | — | Jun 26, 2026 | Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions. |
| CVE-2026-56030 | CRITICAL | 9.8 | — | Jun 26, 2026 | Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions. |
| CVE-2026-56028 | CRITICAL | 9.8 | 0.4% | Jun 26, 2026 | Unauthenticated Privilege Escalation in Easy Elements for Elementor – Addons & Website Templates <= 1.4.9 vers... |
| CVE-2026-56027 | CRITICAL | 9.9 | — | Jun 26, 2026 | Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions. |
| CVE-2026-54831 | CRITICAL | 9.3 | — | Jun 26, 2026 | Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions. |
| CVE-2026-54827 | CRITICAL | 9.3 | — | Jun 26, 2026 | Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions. |
| CVE-2026-54825 | CRITICAL | 9.3 | — | Jun 26, 2026 | Unauthenticated SQL Injection in wpDataTables <= 7.4 versions. |
| CVE-2026-54820 | CRITICAL | 9.3 | — | Jun 26, 2026 | Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions. |
| CVE-2026-57926 | CRITICAL | 9.8 | 0.4% | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack |
| CVE-2026-53914 | CRITICAL | 9.8 | 0.1% | Jun 26, 2026 | In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata |
| CVE-2026-57881 | CRITICAL | 9.8 | 0.4% | Jun 26, 2026 | An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.1... |
| CVE-2026-57880 | CRITICAL | 9.8 | 0.5% | Jun 26, 2026 | An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12... |
| CVE-2026-57879 | CRITICAL | 9.8 | 0.5% | Jun 26, 2026 | An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12... |
| CVE-2026-57878 | CRITICAL | 9.8 | 0.5% | Jun 26, 2026 | An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.... |
| CVE-2026-2053 | CRITICAL | 10 | 0.2% | Jun 26, 2026 | The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or ... |
| CVE-2026-48930 | CRITICAL | 9.8 | 0.3% | Jun 26, 2026 | A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c... |
| CVE-2026-9222 | CRITICAL | 9.2 | 0.2% | Jun 26, 2026 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authe... |
| CVE-2026-40702 | CRITICAL | 9.4 | 0.4% | Jun 25, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a res... |
| CVE-2026-56445 | CRITICAL | 9.1 | 0.4% | Jun 25, 2026 | The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.pa... |
| CVE-2026-7531 | CRITICAL | 9.8 | 0.3% | Jun 25, 2026 | Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1... |
| CVE-2026-57700 | CRITICAL | 10 | 0.4% | Jun 25, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This i... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now