2026 CVE Vulnerabilities
43,937 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48746 | CRITICAL | 9.1 | 1.2% | Jun 22, 2026 | vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in AS... |
| CVE-2026-56348 | CRITICAL | 9.9 | 0.3% | Jun 22, 2026 | n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options end... |
| CVE-2026-48509 | CRITICAL | 9.1 | 0.2% | Jun 22, 2026 | MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless MessagePackInputFor... |
| CVE-2026-49468 | CRITICAL | 9.8 | 0.6% | Jun 22, 2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header par... |
| CVE-2026-45034 | CRITICAL | 9.2 | 0.4% | Jun 22, 2026 | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patc... |
| CVE-2026-12249 | CRITICAL | 9 | 0.1% | Jun 22, 2026 | An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active Directory Certificate Servic... |
| CVE-2026-10789 | CRITICAL | 9.6 | 0.3% | Jun 22, 2026 | A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled... |
| CVE-2026-9072 | CRITICAL | 9.8 | 0.4% | Jun 22, 2026 | IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with t... |
| CVE-2026-9006 | CRITICAL | 9.1 | 0.2% | Jun 22, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy co... |
| CVE-2026-8646 | CRITICAL | 9.1 | 0.3% | Jun 22, 2026 | IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 ar... |
| CVE-2026-7664 | CRITICAL | 9.8 | 0.3% | Jun 22, 2026 | IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and... |
| CVE-2026-12628 | CRITICAL | 9.1 | 0.4% | Jun 22, 2026 | IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 ... |
| CVE-2026-7166 | CRITICAL | 9.2 | 0.4% | Jun 22, 2026 | Vulnerability involving the exposure of sensitive data provided without adequate protection. The API exposes email and p... |
| CVE-2026-7165 | CRITICAL | 9.4 | 0.3% | Jun 22, 2026 | The vulnerability is present in the ‘/addJugador’ endpoint: * The 'keyJugador' and 'keyJugadorObjectiu' parameters a... |
| CVE-2026-6653 | CRITICAL | 9.8 | 0.3% | Jun 22, 2026 | Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker ... |
| CVE-2026-10561 | CRITICAL | 10 | 0.5% | Jun 22, 2026 | IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with... |
| CVE-2026-56422 | CRITICAL | 9.4 | 0.4% | Jun 22, 2026 | Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (i... |
| CVE-2026-11373 | CRITICAL | 9.1 | 0.4% | Jun 22, 2026 | Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for th... |
| CVE-2026-11746 | CRITICAL | 9.4 | 0.1% | Jun 22, 2026 | A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replicatio... |
| CVE-2026-56397 | CRITICAL | 9.6 | 0.4% | Jun 21, 2026 | SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious... |
| CVE-2026-56395 | CRITICAL | 9.6 | 0.4% | Jun 21, 2026 | SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious... |
| CVE-2026-56367 | CRITICAL | 9.1 | 0.2% | Jun 21, 2026 | ImageMagick before 7.1.2-15 and 6.9.x before 6.9.13-40 contains an integer overflow in the PSB (PSD v2) RLE decoding pat... |
| CVE-2026-56265 | CRITICAL | 9.8 | 0.4% | Jun 21, 2026 | Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the ... |
| CVE-2026-12773 | CRITICAL | 9.8 | 0.6% | Jun 21, 2026 | A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file lite... |
| CVE-2026-56345 | CRITICAL | 9.2 | 0.3% | Jun 20, 2026 | AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php end... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now