2026 CVE Vulnerabilities
43,946 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56345 | CRITICAL | 9.2 | 0.3% | Jun 20, 2026 | AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php end... |
| CVE-2026-5366 | CRITICAL | 9.9 | 0.6% | Jun 20, 2026 | Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `... |
| CVE-2026-48939 | CRITICAL | 9.8 | 0.6% | Jun 20, 2026 | A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature... |
| CVE-2026-48909 | CRITICAL | 9.5 | 0.8% | Jun 20, 2026 | SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauth... |
| CVE-2026-48908 | CRITICAL | 9.8 | 1.4% | Jun 20, 2026 | A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulti... |
| CVE-2026-9265 | CRITICAL | 9.1 | 0.4% | Jun 20, 2026 | Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path. print_... |
| CVE-2026-11551 | CRITICAL | 9.8 | 0.6% | Jun 20, 2026 | The Branda plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and in... |
| CVE-2026-56081 | CRITICAL | 9.3 | 0.4% | Jun 19, 2026 | Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker register and control an account bound... |
| CVE-2026-56073 | CRITICAL | 9.4 | 0.2% | Jun 19, 2026 | Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that allows attackers to bypa... |
| CVE-2026-48582 | CRITICAL | 9.6 | 0.4% | Jun 19, 2026 | Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-45480 | CRITICAL | 10 | 0.6% | Jun 19, 2026 | Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-48773 | CRITICAL | 9.8 | 0.7% | Jun 19, 2026 | ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-authenticat... |
| CVE-2026-48772 | CRITICAL | 10 | 0.2% | Jun 19, 2026 | ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL ... |
| CVE-2026-51846 | CRITICAL | 9.8 | 0.6% | Jun 19, 2026 | In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulne... |
| CVE-2026-51845 | CRITICAL | 9.8 | 0.4% | Jun 19, 2026 | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the m... |
| CVE-2026-51844 | CRITICAL | 9.8 | 0.4% | Jun 19, 2026 | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the c... |
| CVE-2026-51843 | CRITICAL | 9.8 | 0.4% | Jun 19, 2026 | Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the w... |
| CVE-2026-9142 | CRITICAL | 9.3 | 0.3% | Jun 19, 2026 | There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the s... |
| CVE-2026-49871 | CRITICAL | 9.3 | 0.3% | Jun 19, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations. This defect allows... |
| CVE-2026-49230 | CRITICAL | 9.1 | 0.2% | Jun 19, 2026 | Improper Validation of Integrity Check Value vulnerability in Apache APISIX. The jwe-decrypt plugin under default confi... |
| CVE-2026-48137 | CRITICAL | 9.8 | 0.5% | Jun 19, 2026 | There is an untrusted pointer dereference vulnerability in the NI grpc-device sideband streaming API that may allow an a... |
| CVE-2026-44087 | CRITICAL | 9.1 | 0.2% | Jun 19, 2026 | Insufficient Verification of Data Authenticity vulnerability in Apache APISIX. The openid-connect plugin under default ... |
| CVE-2026-39999 | CRITICAL | 9.1 | 0.4% | Jun 19, 2026 | Authentication Bypass by Spoofing vulnerability in Apache APISIX. The attacker can completely bypass authentication cap... |
| CVE-2026-56141 | CRITICAL | 9.8 | 0.4% | Jun 19, 2026 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account ... |
| CVE-2026-50242 | CRITICAL | 9.8 | 0.4% | Jun 19, 2026 | In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 authenti... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now