2026 CVE Vulnerabilities
43,970 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-11718 | CRITICAL | 9.3 | 0.2% | Jun 18, 2026 | An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googl... |
| CVE-2026-11717 | CRITICAL | 9.3 | 0.2% | Jun 18, 2026 | An authentication bypass vulnerability exists in the generic opaque token validation path (validateOpaqueToken) of googl... |
| CVE-2026-55742 | CRITICAL | 9.6 | 0.2% | Jun 18, 2026 | Cotonti 1.0.0 (master branch, commit f43f1fc3) is vulnerable to Cross-Site Request Forgery in the administration rights ... |
| CVE-2026-55740 | CRITICAL | 9.8 | 0.4% | Jun 18, 2026 | Nur-Alam39 bus-ticket (no released versions; latest commit 459cabdbeb99c00225b26e46e3c2c30ae1de7bad) contains an unauthe... |
| CVE-2026-12569 | CRITICAL | 9.8 | 2.3% | Jun 18, 2026 | A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vul... |
| CVE-2026-48768 | CRITICAL | 9.3 | 0.3% | Jun 18, 2026 | TypeBot is a chatbot builder tool. In versions 3.16.1 and earlier, POST /api/blocks/file-input/v3/generate-upload-url is... |
| CVE-2026-54388 | CRITICAL | 9.3 | 0.4% | Jun 17, 2026 | Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length headers w... |
| CVE-2026-54387 | CRITICAL | 9.3 | 0.4% | Jun 17, 2026 | Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile conflicting Content-Length and Transfer-Encoding: ... |
| CVE-2026-48814 | CRITICAL | 9.1 | 0.3% | Jun 17, 2026 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. In versions 5.7.1 and earlier, the MCP SSE server allows un... |
| CVE-2026-55196 | CRITICAL | 9.1 | 0.6% | Jun 17, 2026 | Hermes WebUI before 0.51.409 contains an authentication bypass vulnerability in passkey registration endpoints that allo... |
| CVE-2026-53805 | CRITICAL | 9.8 | 0.7% | Jun 17, 2026 | NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inf... |
| CVE-2026-3894 | CRITICAL | 9.1 | 0.2% | Jun 17, 2026 | Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers.This issue affects... |
| CVE-2026-30803 | CRITICAL | 9.1 | 0.3% | Jun 17, 2026 | Integer Underflow (Wrap or Wraparound) vulnerability in RTI Connext Micro (Core Libraries) allows Overread Buffers.This ... |
| CVE-2026-20266 | CRITICAL | 9.1 | 0.5% | Jun 17, 2026 | In Splunk AI Toolkit versions below 5.7.4, a user who holds the "admin" Splunk role could execute arbitrary OS commands ... |
| CVE-2026-53874 | CRITICAL | 9.8 | 0.5% | Jun 17, 2026 | picklescan before 1.0.1 contains an unsafe deserialization vulnerability allowing unauthenticated users to execute arbit... |
| CVE-2026-53873 | CRITICAL | 9.8 | 0.5% | Jun 17, 2026 | picklescan before 1.0.4 contains an incomplete blocklist for the profile module that fails to block the module-level pro... |
| CVE-2026-3490 | CRITICAL | 10 | 0.6% | Jun 17, 2026 | picklescan before 1.0.4 fails to block pkgutil.resolve_name, allowing attackers to bypass the entire blocklist by resolv... |
| CVE-2026-36418 | CRITICAL | 9.1 | 0.5% | Jun 17, 2026 | JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressi... |
| CVE-2026-20181 | CRITICAL | 9.1 | 0.7% | Jun 17, 2026 | A vulnerability in Cisco ISE and ISE-PIC could allow an authenticated, remote attacker to execute arbitrary commands on ... |
| CVE-2026-55743 | CRITICAL | 9.6 | 0.7% | Jun 17, 2026 | The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised sec... |
| CVE-2026-54812 | CRITICAL | 9.3 | 0.3% | Jun 17, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Mot... |
| CVE-2026-47103 | CRITICAL | 9.8 | 1.2% | Jun 17, 2026 | Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to ... |
| CVE-2026-42530 | CRITICAL | 9.2 | 3.2% | Jun 17, 2026 | NGINX Open Source has a vulnerability in the ngx_http_v3_module module. When NGINX Open Source is configured to use the ... |
| CVE-2026-42055 | CRITICAL | 9.2 | 4.3% | Jun 17, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. ... |
| CVE-2026-54819 | CRITICAL | 9.3 | 0.2% | Jun 17, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listd... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now