2026 CVE Vulnerabilities
43,896 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-40079 | CRITICAL | 9.8 | 1.1% | Jun 25, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command ... |
| CVE-2026-39955 | CRITICAL | 9.8 | 0.3% | Jun 24, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have pre-authentication SQ... |
| CVE-2026-39948 | CRITICAL | 9.8 | 0.5% | Jun 24, 2026 | Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request pa... |
| CVE-2026-39938 | CRITICAL | 9.8 | 0.4% | Jun 24, 2026 | Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have unauthenticated LFI t... |
| CVE-2026-55666 | CRITICAL | 9.3 | 0.3% | Jun 24, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, ... |
| CVE-2026-55570 | CRITICAL | 9 | 0.3% | Jun 24, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (... |
| CVE-2026-55455 | CRITICAL | 9.1 | 0.2% | Jun 24, 2026 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the outbound HTTP host filte... |
| CVE-2026-55454 | CRITICAL | 9.9 | 0.3% | Jun 24, 2026 | Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the bundled Caddy reverse-pr... |
| CVE-2026-54158 | CRITICAL | 9.9 | 0.3% | Jun 24, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell render... |
| CVE-2026-54069 | CRITICAL | 9.2 | 0.6% | Jun 24, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan Note's kernel HTTP server uncondit... |
| CVE-2026-54067 | CRITICAL | 9.9 | 0.3% | Jun 24, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> brea... |
| CVE-2026-50551 | CRITICAL | 9.9 | 0.4% | Jun 24, 2026 | SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scrip... |
| CVE-2026-39893 | CRITICAL | 9.8 | 0.4% | Jun 24, 2026 | Cacti is an open source performance and fault management framework. In versions 1.2.30 and prior, the rfilter request va... |
| CVE-2026-52813 | CRITICAL | 10 | 1.1% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences ... |
| CVE-2026-52811 | CRITICAL | 9 | 0.5% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only ... |
| CVE-2026-52806 | CRITICAL | 9.9 | 1.0% | Jun 24, 2026 | Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code ... |
| CVE-2026-46423 | CRITICAL | 9.3 | 0.1% | Jun 24, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, ... |
| CVE-2026-45689 | CRITICAL | 9.1 | 0.3% | Jun 24, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, ... |
| CVE-2026-45688 | CRITICAL | 9.1 | 0.3% | Jun 24, 2026 | Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, ... |
| CVE-2026-33543 | CRITICAL | 9.3 | 0.3% | Jun 24, 2026 | FOSSBilling is a free, open-source billing and client management system. Versions 0.7.2 and prior expose a guest API end... |
| CVE-2026-53943 | CRITICAL | 9.6 | 0.2% | Jun 24, 2026 | Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that resul... |
| CVE-2026-49980 | CRITICAL | 9.8 | 0.8% | Jun 24, 2026 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.46.... |
| CVE-2026-13032 | CRITICAL | 9.6 | 0.2% | Jun 24, 2026 | Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially per... |
| CVE-2026-13028 | CRITICAL | 9.6 | 0.2% | Jun 24, 2026 | Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially per... |
| CVE-2026-54906 | CRITICAL | 9.8 | 0.1% | Jun 24, 2026 | concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReadWriteLock#release_write_lock doe... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now