2026 CVE Vulnerabilities
43,286 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56786 | CRITICAL | 9.8 | 0.4% | Jun 25, 2026 | RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function that fails to clamp lengt... |
| CVE-2026-54917 | CRITICAL | 10 | 0.3% | Jun 25, 2026 | SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the ... |
| CVE-2026-54089 | CRITICAL | 9.1 | 0.3% | Jun 25, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-54088 | CRITICAL | 9.3 | 0.5% | Jun 25, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-50549 | CRITICAL | 9.8 | 0.5% | Jun 25, 2026 | Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by... |
| CVE-2026-50548 | CRITICAL | 9.8 | 0.5% | Jun 25, 2026 | Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by... |
| CVE-2026-6094 | CRITICAL | 9.1 | 0.3% | Jun 25, 2026 | Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically ... |
| CVE-2026-56123 | CRITICAL | 9.8 | 0.3% | Jun 25, 2026 | socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5... |
| CVE-2026-55413 | CRITICAL | 9.4 | 0.3% | Jun 25, 2026 | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI ... |
| CVE-2026-54030 | CRITICAL | 9.3 | 0.1% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.5, LibreChat's MCP OAuth implem... |
| CVE-2026-54849 | CRITICAL | 9.3 | 0.2% | Jun 25, 2026 | Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions. |
| CVE-2026-54843 | CRITICAL | 9.3 | 0.2% | Jun 25, 2026 | Unauthenticated SQL Injection in MDTF <= 1.3.7 versions. |
| CVE-2026-54836 | CRITICAL | 9.3 | 0.2% | Jun 25, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in YMC Filter allows ... |
| CVE-2026-54823 | CRITICAL | 9.9 | 0.4% | Jun 25, 2026 | Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions. |
| CVE-2026-41120 | CRITICAL | 9.8 | 0.3% | Jun 25, 2026 | Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Acceptance of Extraneous Untrusted Data With Trust... |
| CVE-2026-53260 | CRITICAL | 9.8 | 0.3% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: tcp: Add preempt_{disable,enable}_nested() in reqsk... |
| CVE-2026-53247 | CRITICAL | 9.8 | 0.5% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: Fix use-after-free in m... |
| CVE-2026-53246 | CRITICAL | 9.8 | 0.5% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: validate cached peer INIT chunk length in COO... |
| CVE-2026-53228 | CRITICAL | 9.8 | 0.6% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: sit: reload inner IPv6 header after GSO offlo... |
| CVE-2026-53225 | CRITICAL | 9.1 | 0.5% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup(... |
| CVE-2026-53224 | CRITICAL | 9.1 | 0.5% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: sctp: validate embedded INIT chunk and address list... |
| CVE-2026-53221 | CRITICAL | 9.8 | 0.6% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: ip6_vti: fix incorrect tunnel matching in vti6_tnl_... |
| CVE-2026-53216 | CRITICAL | 9.8 | 0.5% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: limit XDP frame size to the RX buffer ... |
| CVE-2026-53215 | CRITICAL | 9.8 | 0.5% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: refill RX buffers before XDP or skb use... |
| CVE-2026-53186 | CRITICAL | 9.1 | 0.5% | Jun 25, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: bound SRP_RSP sense copy by the received ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now