2026 CVE Vulnerabilities
45,454 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47157 | MEDIUM | 6.5 | 0.2% | Jun 11, 2026 | aiograpi is an asynchronous Instagram API for Python. aiograpi versions before 0.9.10 accepted server-supplied signup ch... |
| CVE-2026-46698 | MEDIUM | 5.3 | 0.2% | Jun 11, 2026 | Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.9, Fediverse Embeds registered the unau... |
| CVE-2026-11986 | MEDIUM | 4.9 | 0.3% | Jun 11, 2026 | A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabi... |
| CVE-2026-44489 | MEDIUM | 5.3 | 0.2% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created b... |
| CVE-2026-4096 | MEDIUM | 6.1 | 0.1% | Jun 11, 2026 | IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by th... |
| CVE-2026-3341 | MEDIUM | 5.4 | 0.1% | Jun 11, 2026 | IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allo... |
| CVE-2026-6338 | MEDIUM | 4.9 | 0.3% | Jun 11, 2026 | A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13... |
| CVE-2026-53723 | MEDIUM | 5.8 | 0.2% | Jun 11, 2026 | Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to descri... |
| CVE-2026-49214 | MEDIUM | 5.3 | 0.2% | Jun 11, 2026 | guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII con... |
| CVE-2026-48998 | MEDIUM | 5.3 | 0.2% | Jun 11, 2026 | guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host he... |
| CVE-2026-11956 | MEDIUM | 6.3 | 0.2% | Jun 11, 2026 | A vulnerability was determined in TwiN gatus 5.36.0. Impacted is the function setSessionCookie of the file security/oidc... |
| CVE-2026-9694 | MEDIUM | 4.3 | 0.2% | Jun 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, an... |
| CVE-2026-9204 | MEDIUM | 6.5 | 0.2% | Jun 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8, 18.11 before 18.11.5, a... |
| CVE-2026-6277 | MEDIUM | 4.3 | 0.2% | Jun 11, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 13.9 before 18.10.8, 18.11 before 18.11.5, and 1... |
| CVE-2026-6269 | MEDIUM | 5.4 | 0.2% | Jun 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, a... |
| CVE-2026-53912 | MEDIUM | 5.1 | 0.2% | Jun 11, 2026 | Cerebrate before version 1.37 exposed credential material from self-registration requests. The self-registration workflo... |
| CVE-2026-53423 | MEDIUM | 5.9 | 0.1% | Jun 11, 2026 | Allocation of Resources Without Limits or Throttling vulnerability in membraneframework membrane_mp4_plugin allows unaut... |
| CVE-2026-1500 | MEDIUM | 6.5 | 0.3% | Jun 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.10.8, 18.11 before 18.11.5, a... |
| CVE-2026-10733 | MEDIUM | 4.3 | 0.2% | Jun 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.11 before 18.11.5, an... |
| CVE-2026-53911 | MEDIUM | 6.3 | 0.2% | Jun 11, 2026 | Cerebrate before version 1.37 allowed the id primary key field to be supplied through request input during CRUD edit ope... |
| CVE-2026-11850 | MEDIUM | 5 | 0.3% | Jun 11, 2026 | An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_lda... |
| CVE-2026-41001 | MEDIUM | 5.3 | 0.1% | Jun 11, 2026 | Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's da... |
| CVE-2026-40997 | MEDIUM | 5.3 | 0.4% | Jun 11, 2026 | Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or dis... |
| CVE-2026-40996 | MEDIUM | 4.8 | 0.1% | Jun 11, 2026 | Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for ... |
| CVE-2026-40995 | MEDIUM | 5.4 | 0.1% | Jun 11, 2026 | X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now