2026 CVE Vulnerabilities

61,340 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-53673HIGH8.6BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authen...
CVE-2026-47838HIGH8.1SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead ...
CVE-2026-46545HIGH7.5Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to...
CVE-2026-46543MEDIUM5.3Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to...
CVE-2026-46542MEDIUM4.3Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to...
CVE-2026-46541HIGH7.5Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to...
CVE-2026-46540MEDIUM6.5Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to...
CVE-2026-46539MEDIUM5.9Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to...
CVE-2026-46518HIGH8.7OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio...
CVE-2026-46517HIGH7.8LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardc...
CVE-2026-46491HIGH8.6SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. Prior to versio...
CVE-2026-46432HIGH7.8LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, LMDep...
CVE-2026-46411MEDIUM6.5FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.2, authorized clients have t...
CVE-2026-45782HIGH8.9Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. From version 21.0 to before version 51.2, a guest can...
CVE-2026-44716HIGH7.5Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. From versi...
CVE-2026-44505MEDIUM5.3Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. network-...
CVE-2026-41837MEDIUM5.3Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and...
CVE-2026-41732HIGH8.1JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any pac...
CVE-2026-41731HIGH8.1JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a ...
CVE-2026-41730MEDIUM5.3Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persist...
CVE-2026-41729HIGH8.1Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (app...
CVE-2026-41728HIGH7.5Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to int...
CVE-2026-41727MEDIUM6.5Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on t...
CVE-2026-41726MEDIUM6.5When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending r...
CVE-2026-41721MEDIUM5.9Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Sup...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now