2026 CVE Vulnerabilities
43,897 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12417 | CRITICAL | 9.8 | 0.5% | Jun 24, 2026 | The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leadi... |
| CVE-2026-12416 | CRITICAL | 9.8 | 0.4% | Jun 24, 2026 | The Invoice Generator plugin for WordPress is vulnerable to Account Takeover via Password Reset in all versions up to, a... |
| CVE-2026-12851 | CRITICAL | 9.1 | 1.7% | Jun 24, 2026 | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09... |
| CVE-2026-12850 | CRITICAL | 9.1 | 1.7% | Jun 24, 2026 | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09... |
| CVE-2026-12849 | CRITICAL | 9.1 | 1.7% | Jun 24, 2026 | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09... |
| CVE-2026-12848 | CRITICAL | 10 | 0.4% | Jun 24, 2026 | GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48... |
| CVE-2026-12847 | CRITICAL | 10 | 0.4% | Jun 24, 2026 | GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48... |
| CVE-2026-12846 | CRITICAL | 10 | 0.4% | Jun 24, 2026 | GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48... |
| CVE-2026-12486 | CRITICAL | 9.1 | 1.7% | Jun 24, 2026 | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09... |
| CVE-2026-12485 | CRITICAL | 10 | 0.4% | Jun 24, 2026 | GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-48... |
| CVE-2026-54588 | CRITICAL | 9.6 | 0.3% | Jun 23, 2026 | Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 use the attacke... |
| CVE-2026-11807 | CRITICAL | 9.6 | 0.4% | Jun 23, 2026 | A missing authorization vulnerability was found in the Event-Driven Ansible (EDA) websocket API. The /api/eda/ws/ansible... |
| CVE-2026-53622 | CRITICAL | 10 | 0.2% | Jun 23, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, there is a critical vulnerability in Traefik's HTTP/... |
| CVE-2026-48491 | CRITICAL | 10 | 0.2% | Jun 23, 2026 | Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Tr... |
| CVE-2026-48020 | CRITICAL | 10 | 0.6% | Jun 23, 2026 | Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulner... |
| CVE-2026-53753 | CRITICAL | 10 | 0.4% | Jun 23, 2026 | Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.7, the _safe_eval_expression() function in t... |
| CVE-2026-54316 | CRITICAL | 9.1 | 0.4% | Jun 23, 2026 | Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved ... |
| CVE-2026-54257 | CRITICAL | 9.3 | 0.3% | Jun 23, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.1 unti... |
| CVE-2026-54157 | CRITICAL | 9 | 1.8% | Jun 23, 2026 | LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to ... |
| CVE-2026-53662 | CRITICAL | 9.6 | 0.2% | Jun 23, 2026 | immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a refl... |
| CVE-2026-44726 | CRITICAL | 9.1 | 0.1% | Jun 23, 2026 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.0.0 until 2.7.8, a flaw in Deno's Node.js tls compatib... |
| CVE-2026-55450 | CRITICAL | 9.3 | 0.3% | Jun 23, 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can... |
| CVE-2026-55447 | CRITICAL | 9.6 | 0.4% | Jun 23, 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files th... |
| CVE-2026-54307 | CRITICAL | 9.6 | 0.3% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, a member-level user with edit... |
| CVE-2026-54305 | CRITICAL | 9.9 | 0.3% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints used by th... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now