2026 CVE Vulnerabilities
48,557 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44494 | HIGH | 8.7 | 1.0% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vuln... |
| CVE-2026-44492 | HIGH | 8.6 | 0.9% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise I... |
| CVE-2026-44490 | HIGH | 8.2 | 0.3% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-sid... |
| CVE-2026-44488 | HIGH | 7.5 | 0.6% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce co... |
| CVE-2026-44487 | HIGH | 7.5 | 0.7% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapt... |
| CVE-2026-44486 | HIGH | 7.5 | 0.7% | Jun 11, 2026 | Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapte... |
| CVE-2026-11945 | HIGH | 7.5 | 0.2% | Jun 11, 2026 | PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON docume... |
| CVE-2026-7870 | HIGH | 8.8 | 0.3% | Jun 11, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malici... |
| CVE-2026-7787 | HIGH | 8.1 | 0.2% | Jun 11, 2026 | IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypass... |
| CVE-2026-53777 | HIGH | 8.6 | 0.4% | Jun 11, 2026 | Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary co... |
| CVE-2026-8406 | HIGH | 7.1 | 0.2% | Jun 11, 2026 | openSIS Classic 9.3 contains an insecure direct object reference vulnerability in the messaging module. Any authenticate... |
| CVE-2026-53661 | HIGH | 8.8 | 0.3% | Jun 11, 2026 | Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized iden... |
| CVE-2026-11816 | HIGH | 8.1 | 0.5% | Jun 11, 2026 | Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `... |
| CVE-2026-10847 | HIGH | 7.8 | 0.1% | Jun 11, 2026 | A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated lo... |
| CVE-2026-8589 | HIGH | 8.7 | 0.3% | Jun 11, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and... |
| CVE-2026-8464 | HIGH | 8.3 | 0.2% | Jun 11, 2026 | Golem OEE MES is vulnerable to an unauthenticated path traversal flaw. This vulnerability allows an attacker in the same... |
| CVE-2026-7250 | HIGH | 7.5 | 0.4% | Jun 11, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, a... |
| CVE-2026-10087 | HIGH | 8.7 | 0.2% | Jun 11, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5, and 1... |
| CVE-2026-5497 | HIGH | 7.5 | 0.5% | Jun 11, 2026 | vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded f... |
| CVE-2026-53901 | HIGH | 8.7 | 0.3% | Jun 11, 2026 | Cerebrate before version 1.37 contains a mass-assignment vulnerability in the generic CRUD add path. The add() handler a... |
| CVE-2026-41856 | HIGH | 7.5 | 0.4% | Jun 11, 2026 | The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on... |
| CVE-2026-41700 | HIGH | 8.1 | 0.2% | Jun 11, 2026 | Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacki... |
| CVE-2026-40999 | HIGH | 8.6 | 0.4% | Jun 11, 2026 | When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections ... |
| CVE-2026-40998 | HIGH | 8.2 | 0.4% | Jun 11, 2026 | Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed atta... |
| CVE-2026-40994 | HIGH | 8.2 | 0.2% | Jun 11, 2026 | Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation di... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now