2026 CVE Vulnerabilities
43,894 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54825 | CRITICAL | 9.3 | — | Jun 26, 2026 | Unauthenticated SQL Injection in wpDataTables <= 7.4 versions. |
| CVE-2026-54820 | CRITICAL | 9.3 | — | Jun 26, 2026 | Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions. |
| CVE-2026-57926 | CRITICAL | 9.8 | 0.4% | Jun 26, 2026 | In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack |
| CVE-2026-53914 | CRITICAL | 9.8 | 0.1% | Jun 26, 2026 | In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata |
| CVE-2026-57881 | CRITICAL | 9.8 | 0.4% | Jun 26, 2026 | An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.1... |
| CVE-2026-57880 | CRITICAL | 9.8 | 0.5% | Jun 26, 2026 | An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12... |
| CVE-2026-57879 | CRITICAL | 9.8 | 0.5% | Jun 26, 2026 | An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12... |
| CVE-2026-57878 | CRITICAL | 9.8 | 0.5% | Jun 26, 2026 | An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.... |
| CVE-2026-2053 | CRITICAL | 10 | 0.2% | Jun 26, 2026 | The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or ... |
| CVE-2026-48930 | CRITICAL | 9.8 | 0.3% | Jun 26, 2026 | A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c... |
| CVE-2026-9222 | CRITICAL | 9.2 | 0.2% | Jun 26, 2026 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authe... |
| CVE-2026-40702 | CRITICAL | 9.4 | 0.4% | Jun 25, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a res... |
| CVE-2026-56445 | CRITICAL | 9.1 | 0.4% | Jun 25, 2026 | The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.pa... |
| CVE-2026-7531 | CRITICAL | 9.8 | 0.3% | Jun 25, 2026 | Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1... |
| CVE-2026-57700 | CRITICAL | 10 | 0.4% | Jun 25, 2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This i... |
| CVE-2026-56786 | CRITICAL | 9.8 | 0.4% | Jun 25, 2026 | RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function that fails to clamp lengt... |
| CVE-2026-54917 | CRITICAL | 10 | 0.3% | Jun 25, 2026 | SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the ... |
| CVE-2026-54089 | CRITICAL | 9.1 | 0.3% | Jun 25, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-54088 | CRITICAL | 9.3 | 0.5% | Jun 25, 2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a spec... |
| CVE-2026-50549 | CRITICAL | 9.8 | 0.5% | Jun 25, 2026 | Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by... |
| CVE-2026-50548 | CRITICAL | 9.8 | 0.5% | Jun 25, 2026 | Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by... |
| CVE-2026-6094 | CRITICAL | 9.1 | 0.3% | Jun 25, 2026 | Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically ... |
| CVE-2026-56123 | CRITICAL | 9.8 | 0.3% | Jun 25, 2026 | socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5... |
| CVE-2026-55413 | CRITICAL | 9.4 | 0.3% | Jun 25, 2026 | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI ... |
| CVE-2026-54030 | CRITICAL | 9.3 | 0.1% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.5, LibreChat's MCP OAuth implem... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now