2026 CVE Vulnerabilities

46,854 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-49214MEDIUM5.3guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII con...
CVE-2026-48998MEDIUM5.3guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host he...
CVE-2026-11956MEDIUM6.3A vulnerability was determined in TwiN gatus 5.36.0. Impacted is the function setSessionCookie of the file security/oidc...
CVE-2026-9694MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, an...
CVE-2026-9204MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8, 18.11 before 18.11.5, a...
CVE-2026-6277MEDIUM4.3GitLab has remediated an issue in GitLab EE affecting all versions from 13.9 before 18.10.8, 18.11 before 18.11.5, and 1...
CVE-2026-6269MEDIUM5.4GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, a...
CVE-2026-53912MEDIUM5.1Cerebrate before version 1.37 exposed credential material from self-registration requests. The self-registration workflo...
CVE-2026-53423MEDIUM5.9Allocation of Resources Without Limits or Throttling vulnerability in membraneframework membrane_mp4_plugin allows unaut...
CVE-2026-1500MEDIUM6.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.10.8, 18.11 before 18.11.5, a...
CVE-2026-10733MEDIUM4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.11 before 18.11.5, an...
CVE-2026-53911MEDIUM6.3Cerebrate before version 1.37 allowed the id primary key field to be supplied through request input during CRUD edit ope...
CVE-2026-11850MEDIUM5An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_lda...
CVE-2026-41001MEDIUM5.3Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's da...
CVE-2026-40997MEDIUM5.3Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or dis...
CVE-2026-40996MEDIUM4.8Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for ...
CVE-2026-40995MEDIUM5.4X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped...
CVE-2026-40992MEDIUM5Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail...
CVE-2026-40986MEDIUM4.8Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not...
CVE-2026-40985MEDIUM6.4Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions....
CVE-2026-2827MEDIUM4.7The Open User Map PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'oum_location_notificati...
CVE-2026-53465MEDIUM6.2ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25...
CVE-2026-53464MEDIUM4ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25...
CVE-2026-53463MEDIUM4.3ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-53462MEDIUM5.9ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now