2026 CVE Vulnerabilities
61,333 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6277 | MEDIUM | 4.3 | 0.2% | Jun 11, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 13.9 before 18.10.8, 18.11 before 18.11.5, and 1... |
| CVE-2026-6269 | MEDIUM | 5.4 | 0.2% | Jun 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, a... |
| CVE-2026-53912 | MEDIUM | 5.1 | 0.2% | Jun 11, 2026 | Cerebrate before version 1.37 exposed credential material from self-registration requests. The self-registration workflo... |
| CVE-2026-53423 | MEDIUM | 5.9 | 0.1% | Jun 11, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in membraneframework membrane_mp4_plugin allows unaut... |
| CVE-2026-4764 | CRITICAL | 9.4 | 0.2% | Jun 11, 2026 | A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform all... |
| CVE-2026-3553 | LOW | 3.1 | 0.2% | Jun 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, an... |
| CVE-2026-1500 | MEDIUM | 6.5 | 0.3% | Jun 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.10.8, 18.11 before 18.11.5, a... |
| CVE-2026-10733 | MEDIUM | 4.3 | 0.2% | Jun 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.11 before 18.11.5, an... |
| CVE-2026-10087 | HIGH | 8.7 | 0.2% | Jun 11, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5, and 1... |
| CVE-2026-5497 | HIGH | 7.5 | 0.5% | Jun 11, 2026 | vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded f... |
| CVE-2026-53911 | MEDIUM | 6.3 | 0.2% | Jun 11, 2026 | Cerebrate before version 1.37 allowed the id primary key field to be supplied through request input during CRUD edit ope... |
| CVE-2026-11850 | MEDIUM | 5 | 0.3% | Jun 11, 2026 | An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_lda... |
| CVE-2026-53901 | HIGH | 8.7 | 0.3% | Jun 11, 2026 | Cerebrate before version 1.37 contains a mass-assignment vulnerability in the generic CRUD add path. The add() handler a... |
| CVE-2026-41856 | HIGH | 7.5 | 0.4% | Jun 11, 2026 | The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on... |
| CVE-2026-41700 | HIGH | 8.1 | 0.2% | Jun 11, 2026 | Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacki... |
| CVE-2026-41699 | CRITICAL | 9.8 | 0.4% | Jun 11, 2026 | Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An a... |
| CVE-2026-41001 | MEDIUM | 5.3 | 0.1% | Jun 11, 2026 | Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's da... |
| CVE-2026-41000 | LOW | 3.7 | 0.2% | Jun 11, 2026 | Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-ti... |
| CVE-2026-40999 | HIGH | 8.6 | 0.4% | Jun 11, 2026 | When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections ... |
| CVE-2026-40998 | HIGH | 8.2 | 0.4% | Jun 11, 2026 | Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed atta... |
| CVE-2026-40997 | MEDIUM | 5.3 | 0.4% | Jun 11, 2026 | Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or dis... |
| CVE-2026-40996 | MEDIUM | 4.8 | 0.1% | Jun 11, 2026 | Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for ... |
| CVE-2026-40995 | MEDIUM | 5.4 | 0.1% | Jun 11, 2026 | X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped... |
| CVE-2026-40994 | HIGH | 8.2 | 0.2% | Jun 11, 2026 | Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation di... |
| CVE-2026-40992 | MEDIUM | 5 | 0.1% | Jun 11, 2026 | Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now