2026 CVE Vulnerabilities
47,130 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41844 | MEDIUM | 6.1 | 0.1% | Jun 9, 2026 | A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly sp... |
| CVE-2026-41843 | MEDIUM | 5.9 | 0.3% | Jun 9, 2026 | Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected ... |
| CVE-2026-41841 | MEDIUM | 5.9 | 0.3% | Jun 9, 2026 | Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. A... |
| CVE-2026-41840 | MEDIUM | 5.9 | 0.2% | Jun 9, 2026 | Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affect... |
| CVE-2026-41839 | MEDIUM | 4.2 | 0.2% | Jun 9, 2026 | A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerab... |
| CVE-2026-41715 | MEDIUM | 6.1 | 0.2% | Jun 9, 2026 | In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may ... |
| CVE-2026-41710 | MEDIUM | 5.9 | 0.3% | Jun 9, 2026 | An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the applicati... |
| CVE-2026-11623 | MEDIUM | 4.5 | 0.1% | Jun 9, 2026 | A security vulnerability has been detected in tmux up to 3.6a. Affected is the function image_free of the file image.c. ... |
| CVE-2026-11603 | MEDIUM | 6.1 | 0.2% | Jun 9, 2026 | The Product Filter Widget for Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'args[f... |
| CVE-2026-10738 | MEDIUM | 6.4 | 0.3% | Jun 9, 2026 | The jQuery Hover Footnotes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Footnote Qualifier ('{{... |
| CVE-2026-10553 | MEDIUM | 4.3 | 0.1% | Jun 9, 2026 | The jQuery Hover Footnotes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i... |
| CVE-2026-10024 | MEDIUM | 6.4 | 0.2% | Jun 9, 2026 | The TinyMCE shortcode Addon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'btnrel' Shortcode Att... |
| CVE-2026-5714 | MEDIUM | 6.4 | 0.2% | Jun 9, 2026 | The Enable Media Replace plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘location_dir’ parame... |
| CVE-2026-11621 | MEDIUM | 4.7 | 0.2% | Jun 9, 2026 | A weakness has been identified in Dcat-Admin up to 2.2.3-beta. This impacts the function editorMDUpload of the file /adm... |
| CVE-2026-11620 | MEDIUM | 5.5 | 0.3% | Jun 9, 2026 | A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. This affects an unknown function of the file /etc/vsf... |
| CVE-2026-11619 | MEDIUM | 6.3 | 0.2% | Jun 9, 2026 | A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. The impacted element is an unknown function of the file... |
| CVE-2026-10862 | MEDIUM | 6.4 | 0.2% | Jun 9, 2026 | The Accordions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Accordion body field in all ver... |
| CVE-2026-44757 | MEDIUM | 4.7 | 0.2% | Jun 9, 2026 | SAP Wily Introscope Enterprise Manager allows an unauthenticated attacker to craft a specially crafted URL. Under certai... |
| CVE-2026-44755 | MEDIUM | 4.3 | 0.1% | Jun 9, 2026 | SAP Business Objects Business Intelligence Platform does not sufficiently validate email sending parameters supplied by ... |
| CVE-2026-44754 | MEDIUM | 6.6 | 0.2% | Jun 9, 2026 | The Remote Function Call (RFC) modules of the Operational Data Provisioning Data Replication API (ODP-RFC) are missing c... |
| CVE-2026-44750 | MEDIUM | 4.3 | 0.2% | Jun 9, 2026 | SAP MDG (Review Match Groups Application) does not perform the necessary authorization checks for authenticated users. T... |
| CVE-2026-44746 | MEDIUM | 6.1 | 0.2% | Jun 9, 2026 | Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver JAVA (JDBC Test Servlet), an unauthenticate... |
| CVE-2026-44744 | MEDIUM | 6.5 | 0.2% | Jun 9, 2026 | SAP S/4HANA(On-Premise) contains SQL injection vulnerability in a remote-enabled function module component that could be... |
| CVE-2026-24315 | MEDIUM | 4.2 | 0.2% | Jun 9, 2026 | SAP Fiori Launchpad allows attackers to craft malicious URLs that triggers arbitrary service calls on the Fiori domain, ... |
| CVE-2026-11701 | MEDIUM | 5.4 | 0.2% | Jun 9, 2026 | Inappropriate implementation in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to perform... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now