2026 CVE Vulnerabilities
44,013 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-27429 | CRITICAL | 9.8 | 0.6% | Jun 17, 2026 | Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions. |
| CVE-2026-27395 | CRITICAL | 9.8 | 0.3% | Jun 17, 2026 | Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions. |
| CVE-2026-27041 | CRITICAL | 9.9 | 0.3% | Jun 17, 2026 | Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions. |
| CVE-2026-25470 | CRITICAL | 10 | 0.4% | Jun 17, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin fo... |
| CVE-2026-25446 | CRITICAL | 9.9 | 0.4% | Jun 17, 2026 | Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions. |
| CVE-2026-24611 | CRITICAL | 9.1 | 0.4% | Jun 17, 2026 | Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions. |
| CVE-2026-22340 | CRITICAL | 9.3 | 0.4% | Jun 17, 2026 | Unauthenticated SQL Injection in WPJobster <= 6.3.5 versions. |
| CVE-2026-22332 | CRITICAL | 9.3 | 0.3% | Jun 17, 2026 | Unauthenticated SQL Injection in Tutor LMS Pro <= 3.9.6 versions. |
| CVE-2026-22327 | CRITICAL | 9.9 | 0.5% | Jun 17, 2026 | Subscriber Arbitrary File Upload in Restaurt <= 1.0.4 versions. |
| CVE-2026-12440 | CRITICAL | 9.6 | 0.3% | Jun 17, 2026 | Use after free in DigitalCredentials in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to po... |
| CVE-2026-10094 | CRITICAL | 9.8 | 0.4% | Jun 17, 2026 | A Path Traversal vulnerability affecting SOLIDWORKS Visualize from SOLIDWORKS Desktop Release 2024 through SOLIDWORKS De... |
| CVE-2026-0092 | CRITICAL | 10 | 0.2% | Jun 17, 2026 | In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead... |
| CVE-2026-48776 | CRITICAL | 9.1 | 0.2% | Jun 17, 2026 | LangGraph Python SDK is used to connect to running LangGraph API servers, manage assistants, threads and stream runs fro... |
| CVE-2026-46978 | CRITICAL | 10 | 0.3% | Jun 17, 2026 | Vulnerability in the Oracle Solaris product of Oracle Systems (component: Remote Administration Daemon). The supported... |
| CVE-2026-46964 | CRITICAL | 9.9 | 0.4% | Jun 17, 2026 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level... |
| CVE-2026-46963 | CRITICAL | 9.9 | 0.4% | Jun 17, 2026 | Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Site Level... |
| CVE-2026-46949 | CRITICAL | 9.1 | 0.4% | Jun 17, 2026 | Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: Internal Operatio... |
| CVE-2026-46946 | CRITICAL | 9.1 | 0.5% | Jun 17, 2026 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported ver... |
| CVE-2026-46945 | CRITICAL | 9.1 | 0.5% | Jun 17, 2026 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported ver... |
| CVE-2026-46944 | CRITICAL | 9.1 | 0.5% | Jun 17, 2026 | Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Internal Operations). Supported ver... |
| CVE-2026-46933 | CRITICAL | 9.9 | 0.4% | Jun 17, 2026 | Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Internal Operations). S... |
| CVE-2026-46930 | CRITICAL | 9.1 | 0.4% | Jun 17, 2026 | Vulnerability in the Oracle In-Memory Cost Management for Discrete Industries product of Oracle E-Business Suite (compon... |
| CVE-2026-46919 | CRITICAL | 9.8 | 0.4% | Jun 17, 2026 | Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp... |
| CVE-2026-46918 | CRITICAL | 9.9 | 0.4% | Jun 17, 2026 | Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Int... |
| CVE-2026-46913 | CRITICAL | 9.3 | 0.1% | Jun 17, 2026 | Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Installation Security). Su... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now