2026 CVE Vulnerabilities
43,990 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48797 | CRITICAL | 9.3 | 0.3% | Jun 17, 2026 | Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, th... |
| CVE-2026-48781 | CRITICAL | 9.9 | 0.2% | Jun 17, 2026 | Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an atta... |
| CVE-2026-48745 | CRITICAL | 9.3 | 0.3% | Jun 17, 2026 | Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Tracca... |
| CVE-2026-48616 | CRITICAL | 9.3 | 0.3% | Jun 17, 2026 | Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in L... |
| CVE-2026-48055 | CRITICAL | 10 | 0.6% | Jun 17, 2026 | Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior,... |
| CVE-2026-42380 | CRITICAL | 9.8 | 0.5% | Jun 17, 2026 | Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions. |
| CVE-2026-40783 | CRITICAL | 9.9 | 0.5% | Jun 17, 2026 | Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions. |
| CVE-2026-40749 | CRITICAL | 9.9 | 0.4% | Jun 17, 2026 | Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions. |
| CVE-2026-40748 | CRITICAL | 9.9 | 0.4% | Jun 17, 2026 | Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions. |
| CVE-2026-40747 | CRITICAL | 9.9 | 0.4% | Jun 17, 2026 | Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions. |
| CVE-2026-40746 | CRITICAL | 9.9 | 0.4% | Jun 17, 2026 | Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions. |
| CVE-2026-40725 | CRITICAL | 9.8 | 0.4% | Jun 17, 2026 | Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions. |
| CVE-2026-39596 | CRITICAL | 9.3 | 0.4% | Jun 17, 2026 | Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions. |
| CVE-2026-39589 | CRITICAL | 9.9 | 0.4% | Jun 17, 2026 | Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions. |
| CVE-2026-39529 | CRITICAL | 9.8 | 0.4% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions. |
| CVE-2026-39438 | CRITICAL | 9.3 | 0.4% | Jun 17, 2026 | Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions. |
| CVE-2026-32967 | CRITICAL | 9.1 | 0.3% | Jun 17, 2026 | Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Ap... |
| CVE-2026-32966 | CRITICAL | 9.8 | 0.4% | Jun 17, 2026 | DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler... |
| CVE-2026-27429 | CRITICAL | 9.8 | 0.6% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions. |
| CVE-2026-27395 | CRITICAL | 9.8 | 0.3% | Jun 17, 2026 | Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions. |
| CVE-2026-27041 | CRITICAL | 9.9 | 0.3% | Jun 17, 2026 | Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions. |
| CVE-2026-25470 | CRITICAL | 10 | 0.4% | Jun 17, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin fo... |
| CVE-2026-25446 | CRITICAL | 9.9 | 0.4% | Jun 17, 2026 | Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions. |
| CVE-2026-24611 | CRITICAL | 9.1 | 0.4% | Jun 17, 2026 | Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions. |
| CVE-2026-22340 | CRITICAL | 9.3 | 0.4% | Jun 17, 2026 | Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now