2026 CVE Vulnerabilities
46,870 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-46532 | MEDIUM | 4.6 | 0.2% | Jun 10, 2026 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.3, and 6.0... |
| CVE-2026-45329 | MEDIUM | 6.5 | 0.1% | Jun 10, 2026 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secu... |
| CVE-2026-45160 | MEDIUM | 6.5 | 0.2% | Jun 10, 2026 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5.4.4, 5.5.4, and 6.0... |
| CVE-2026-46546 | MEDIUM | 5.4 | 0.1% | Jun 10, 2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version ... |
| CVE-2026-53675 | MEDIUM | 5.3 | 0.2% | Jun 10, 2026 | BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any aut... |
| CVE-2026-46543 | MEDIUM | 5.3 | 0.3% | Jun 10, 2026 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to... |
| CVE-2026-46542 | MEDIUM | 4.3 | 0.2% | Jun 10, 2026 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to... |
| CVE-2026-46540 | MEDIUM | 6.5 | 0.3% | Jun 10, 2026 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to... |
| CVE-2026-46539 | MEDIUM | 5.9 | 0.1% | Jun 10, 2026 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to... |
| CVE-2026-46411 | MEDIUM | 6.5 | 0.3% | Jun 10, 2026 | FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.2, authorized clients have t... |
| CVE-2026-44505 | MEDIUM | 5.3 | 0.3% | Jun 10, 2026 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. network-... |
| CVE-2026-41837 | MEDIUM | 5.3 | 0.2% | Jun 10, 2026 | Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and... |
| CVE-2026-41730 | MEDIUM | 5.3 | 0.2% | Jun 10, 2026 | Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persist... |
| CVE-2026-41727 | MEDIUM | 6.5 | 0.2% | Jun 10, 2026 | Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on t... |
| CVE-2026-41726 | MEDIUM | 6.5 | 0.3% | Jun 10, 2026 | When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending r... |
| CVE-2026-41721 | MEDIUM | 5.9 | 0.3% | Jun 10, 2026 | Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Sup... |
| CVE-2026-41719 | MEDIUM | 6.4 | 0.2% | Jun 10, 2026 | A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a rep... |
| CVE-2026-41714 | MEDIUM | 4 | 0.1% | Jun 10, 2026 | Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also c... |
| CVE-2026-41711 | MEDIUM | 5.9 | 0.3% | Jun 10, 2026 | Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowE... |
| CVE-2026-41706 | MEDIUM | 6.1 | 0.2% | Jun 10, 2026 | Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser ... |
| CVE-2026-41701 | MEDIUM | 4.4 | 0.2% | Jun 10, 2026 | Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to int... |
| CVE-2026-41697 | MEDIUM | 4.8 | 0.2% | Jun 10, 2026 | Spring Data Relational does not properly escape binding values of externally-controlled input when using StringMatcher (... |
| CVE-2026-41696 | MEDIUM | 5.9 | 0.3% | Jun 10, 2026 | Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient... |
| CVE-2026-41694 | MEDIUM | 5.3 | 0.1% | Jun 10, 2026 | Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses withou... |
| CVE-2026-41008 | MEDIUM | 6.1 | 0.2% | Jun 10, 2026 | Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parame... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now