2026 CVE Vulnerabilities
48,557 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41856 | HIGH | 7.5 | 0.4% | Jun 11, 2026 | The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on... |
| CVE-2026-41700 | HIGH | 8.1 | 0.2% | Jun 11, 2026 | Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacki... |
| CVE-2026-40999 | HIGH | 8.6 | 0.4% | Jun 11, 2026 | When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections ... |
| CVE-2026-40998 | HIGH | 8.2 | 0.4% | Jun 11, 2026 | Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed atta... |
| CVE-2026-40994 | HIGH | 8.2 | 0.2% | Jun 11, 2026 | Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation di... |
| CVE-2026-40987 | HIGH | 7.1 | 0.2% | Jun 11, 2026 | A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the ... |
| CVE-2026-10795 | HIGH | 8.1 | 3.6% | Jun 11, 2026 | The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all version... |
| CVE-2026-53461 | HIGH | 7.5 | 0.4% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-53460 | HIGH | 7.5 | 0.3% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-52726 | HIGH | 7.5 | 0.4% | Jun 10, 2026 | Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.23.2 and prior to v... |
| CVE-2026-50223 | HIGH | 8.8 | 0.7% | Jun 10, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenti... |
| CVE-2026-49218 | HIGH | 7.5 | 0.3% | Jun 10, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-... |
| CVE-2026-47342 | HIGH | 8.8 | 0.4% | Jun 10, 2026 | A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privile... |
| CVE-2026-44693 | HIGH | 8.8 | 0.2% | Jun 10, 2026 | Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. Prior to version 6.6.1, P... |
| CVE-2026-42563 | HIGH | 7.7 | 0.6% | Jun 10, 2026 | Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to v... |
| CVE-2026-42558 | HIGH | 7.6 | 0.1% | Jun 10, 2026 | Xibo is an open source digital signage platform with a web content management system and Windows display player software... |
| CVE-2026-42305 | HIGH | 8.8 | 0.6% | Jun 10, 2026 | Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and prior t... |
| CVE-2026-53738 | HIGH | 8.1 | 0.2% | Jun 10, 2026 | Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handli... |
| CVE-2026-50131 | HIGH | 8.6 | 0.3% | Jun 10, 2026 | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Fedify previously addressed SS... |
| CVE-2026-48110 | HIGH | 7.5 | 0.3% | Jun 10, 2026 | Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.0, several russh client and serv... |
| CVE-2026-46702 | HIGH | 7.5 | 0.3% | Jun 10, 2026 | Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.1, when SSH compression is enabl... |
| CVE-2026-46689 | HIGH | 8.7 | 0.3% | Jun 10, 2026 | Kanidm is an identity management platform. Prior to version 1.9.3, a single unauthenticated GET to any /scim/v1/... endp... |
| CVE-2026-46679 | HIGH | 7.5 | 0.3% | Jun 10, 2026 | libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 15.0.23, three cooperating omissions ... |
| CVE-2026-46673 | HIGH | 7.5 | 0.3% | Jun 10, 2026 | Russh is a Rust SSH client & server library. Prior to version 0.60.3, CryptoVec used unchecked capacity growth, unchecke... |
| CVE-2026-46669 | HIGH | 7.5 | 0.2% | Jun 10, 2026 | OpenVM is a performant and modular zkVM framework built for customization and extensibility. Prior to version 1.6.0, the... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now