2026 CVE Vulnerabilities
43,950 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8713 | CRITICAL | 9.1 | 1.2% | Jun 19, 2026 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path v... |
| CVE-2026-7515 | CRITICAL | 9.8 | 0.9% | Jun 19, 2026 | The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 vi... |
| CVE-2026-54414 | CRITICAL | 9.8 | 1.1% | Jun 19, 2026 | FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedF... |
| CVE-2026-40624 | CRITICAL | 9.8 | 0.6% | Jun 19, 2026 | Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated att... |
| CVE-2026-12046 | CRITICAL | 9.5 | 0.7% | Jun 19, 2026 | Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqledit... |
| CVE-2026-47647 | CRITICAL | 9.9 | 0.4% | Jun 18, 2026 | Improper access control in Microsoft Dynamics 365 allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-49454 | CRITICAL | 9.1 | 0.1% | Jun 18, 2026 | Relyra is a strict-by-default SAML 2.0 Service Provider library for Elixir and Phoenix. Versions 1.0.0 and 1.1.0 accept ... |
| CVE-2026-49257 | CRITICAL | 10 | 0.5% | Jun 18, 2026 | mcp-pinot is a Python-based Model Context Protocol (MCP) server for interacting with Apache Pinot. In versions 3.0.1 and... |
| CVE-2026-49252 | CRITICAL | 9.9 | 0.3% | Jun 18, 2026 | deepstream is a server that allows clients and backend services to sync data, send messages and make rpcs at scale. Vers... |
| CVE-2026-43994 | CRITICAL | 9.8 | 0.4% | Jun 18, 2026 | Coturn is a free open source implementation of TURN and STUN Server. Versions prior to 4.10.0 contain a stack buffer ove... |
| CVE-2026-47846 | CRITICAL | 9.8 | 0.3% | Jun 18, 2026 | Bitnami Cassandra container images are affected by a retained default superuser vulnerability. When a custom administrat... |
| CVE-2026-54390 | CRITICAL | 9.8 | 0.3% | Jun 18, 2026 | JTL Shop versions 5.2.0 through 5.7.1 contains a server-side template injection vulnerability that allows unauthenticate... |
| CVE-2026-56020 | CRITICAL | 9.2 | 0.5% | Jun 18, 2026 | The Webmin HTTP server (miniserv.pl) allows unauthenticated attackers to impersonate any user with a configured SSL clie... |
| CVE-2026-55203 | CRITICAL | 9.1 | 0.3% | Jun 18, 2026 | HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's ... |
| CVE-2026-54103 | CRITICAL | 9.8 | 0.4% | Jun 18, 2026 | The U.S. Government Accountability Office (GAO) Electronic Protest Docketing System (EPDS) and Civilian Board of Contrac... |
| CVE-2026-38717 | CRITICAL | 9.8 | 1.3% | Jun 18, 2026 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a co... |
| CVE-2026-38716 | CRITICAL | 9.8 | 1.3% | Jun 18, 2026 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a co... |
| CVE-2026-38715 | CRITICAL | 9.8 | 1.3% | Jun 18, 2026 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a co... |
| CVE-2026-38714 | CRITICAL | 9.8 | 1.3% | Jun 18, 2026 | InHand Networks IR912 V1.0.0.r20042 and IR915 V1.0.0.r20042 (including earlier versions) were discovered to contain a co... |
| CVE-2026-9158 | CRITICAL | 9.8 | 0.2% | Jun 18, 2026 | In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interfac... |
| CVE-2026-8024 | CRITICAL | 9.8 | 0.6% | Jun 18, 2026 | A remote, unauthenticated attacker may exploit a deserialization of untrusted data vulnerability in ibaPDA or ibaDatCoor... |
| CVE-2026-54419 | CRITICAL | 9.8 | 0.6% | Jun 18, 2026 | claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management System; no released versions, latest commit 389d2633441b65ced1... |
| CVE-2026-11718 | CRITICAL | 9.3 | 0.2% | Jun 18, 2026 | An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googl... |
| CVE-2026-11717 | CRITICAL | 9.3 | 0.2% | Jun 18, 2026 | An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googl... |
| CVE-2026-55742 | CRITICAL | 9.6 | 0.2% | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now