2026 CVE Vulnerabilities
46,876 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41008 | MEDIUM | 6.1 | 0.2% | Jun 10, 2026 | Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parame... |
| CVE-2026-41003 | MEDIUM | 5.4 | 0.2% | Jun 10, 2026 | An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generat... |
| CVE-2026-40991 | MEDIUM | 5.9 | 0.2% | Jun 10, 2026 | When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an ... |
| CVE-2026-9751 | MEDIUM | 6.8 | 0.1% | Jun 9, 2026 | The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mon... |
| CVE-2026-9742 | MEDIUM | 5.9 | 0.3% | Jun 9, 2026 | When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of th... |
| CVE-2026-9735 | MEDIUM | 6.8 | 0.1% | Jun 9, 2026 | MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. W... |
| CVE-2026-46433 | MEDIUM | 6.5 | 0.2% | Jun 9, 2026 | lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1.0.22, lldpd_decode() in src/daemon/lldpd.c strips ... |
| CVE-2026-47905 | MEDIUM | 6.2 | 0.2% | Jun 9, 2026 | CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu... |
| CVE-2026-47904 | MEDIUM | 6.2 | 0.2% | Jun 9, 2026 | CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu... |
| CVE-2026-47903 | MEDIUM | 6.2 | 0.2% | Jun 9, 2026 | CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation v... |
| CVE-2026-47902 | MEDIUM | 6.2 | 0.2% | Jun 9, 2026 | CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consu... |
| CVE-2026-34657 | MEDIUM | 5.5 | 0.2% | Jun 9, 2026 | CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Limitation of a Pa... |
| CVE-2026-34417 | MEDIUM | 6.1 | 0.2% | Jun 9, 2026 | OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbit... |
| CVE-2026-25860 | MEDIUM | 6.1 | 0.3% | Jun 9, 2026 | OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that al... |
| CVE-2026-47961 | MEDIUM | 5.5 | 0.2% | Jun 9, 2026 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that ... |
| CVE-2026-47933 | MEDIUM | 4.8 | 0.2% | Jun 9, 2026 | ColdFusion versions 2023.19, 2025.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that c... |
| CVE-2026-47926 | MEDIUM | 5.5 | 0.2% | Jun 9, 2026 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that ... |
| CVE-2026-47925 | MEDIUM | 5.5 | 0.1% | Jun 9, 2026 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Integer Overflow or Wraparound vulnera... |
| CVE-2026-47924 | MEDIUM | 5.5 | 0.3% | Jun 9, 2026 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Use After Free vulnerability that could... |
| CVE-2026-47923 | MEDIUM | 5.5 | 0.2% | Jun 9, 2026 | Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that ... |
| CVE-2026-34416 | MEDIUM | 6.1 | 0.2% | Jun 9, 2026 | OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbit... |
| CVE-2026-25557 | MEDIUM | 5.4 | 0.2% | Jun 9, 2026 | Evoluted PHP Directory Listing Script through 4.0.5 contains a reflected cross-site scripting vulnerability in index.php... |
| CVE-2026-47910 | MEDIUM | 6.3 | 0.1% | Jun 9, 2026 | Dreamweaver Desktop versions 21.7 and earlier are affected by an Incorrect Authorization vulnerability that could lead t... |
| CVE-2026-47909 | MEDIUM | 6.3 | 0.1% | Jun 9, 2026 | Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Input Validation vulnerability that could lead... |
| CVE-2026-47106 | MEDIUM | 5.4 | 0.2% | Jun 9, 2026 | Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a stored cross-site scripting vulnerabili... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now