2026 CVE Vulnerabilities

46,870 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-46532MEDIUM4.6ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.3, and 6.0...
CVE-2026-45329MEDIUM6.5ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secu...
CVE-2026-45160MEDIUM6.5ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5.4.4, 5.5.4, and 6.0...
CVE-2026-46546MEDIUM5.4Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version ...
CVE-2026-53675MEDIUM5.3BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any aut...
CVE-2026-46543MEDIUM5.3Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to...
CVE-2026-46542MEDIUM4.3Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to...
CVE-2026-46540MEDIUM6.5Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to...
CVE-2026-46539MEDIUM5.9Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to...
CVE-2026-46411MEDIUM6.5FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.2, authorized clients have t...
CVE-2026-44505MEDIUM5.3Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. network-...
CVE-2026-41837MEDIUM5.3Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and...
CVE-2026-41730MEDIUM5.3Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persist...
CVE-2026-41727MEDIUM6.5Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on t...
CVE-2026-41726MEDIUM6.5When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending r...
CVE-2026-41721MEDIUM5.9Spring Data Commons contains a vulnerability that can lead to a Denial of Service (DoS) condition if Spring Data Web Sup...
CVE-2026-41719MEDIUM6.4A SpEL Injection vulnerability exists in the Spring Data KeyValue if unsanitized user input is passed as Sort into a rep...
CVE-2026-41714MEDIUM4Applications that configure their broker connection via RabbitConnectionFactoryBean.setUri("amqps://...") without also c...
CVE-2026-41711MEDIUM5.9Applications using Spring Data Commons may be vulnerable to a Denial of Service (DoS) attack leading to a StackOverflowE...
CVE-2026-41706MEDIUM6.1Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser ...
CVE-2026-41701MEDIUM4.4Correlation IDs for replies in the RabbitTemplate.sendAndReceive() with the fixed reply queue are predictable due to int...
CVE-2026-41697MEDIUM4.8Spring Data Relational does not properly escape binding values of externally-controlled input when using StringMatcher (...
CVE-2026-41696MEDIUM5.9Spring Data MongoDB repository query methods annotated with @Query that use regex parameter binding perform insufficient...
CVE-2026-41694MEDIUM5.3Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses withou...
CVE-2026-41008MEDIUM6.1Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parame...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now