2026 CVE Vulnerabilities

48,557 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-41856HIGH7.5The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on...
CVE-2026-41700HIGH8.1Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacki...
CVE-2026-40999HIGH8.6When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections ...
CVE-2026-40998HIGH8.2Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed atta...
CVE-2026-40994HIGH8.2Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation di...
CVE-2026-40987HIGH7.1A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the ...
CVE-2026-10795HIGH8.1The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all version...
CVE-2026-53461HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-53460HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-52726HIGH7.5Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.23.2 and prior to v...
CVE-2026-50223HIGH8.8Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenti...
CVE-2026-49218HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-47342HIGH8.8A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privile...
CVE-2026-44693HIGH8.8Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. Prior to version 6.6.1, P...
CVE-2026-42563HIGH7.7Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to v...
CVE-2026-42558HIGH7.6Xibo is an open source digital signage platform with a web content management system and Windows display player software...
CVE-2026-42305HIGH8.8Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and prior t...
CVE-2026-53738HIGH8.1Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handli...
CVE-2026-50131HIGH8.6Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Fedify previously addressed SS...
CVE-2026-48110HIGH7.5Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.0, several russh client and serv...
CVE-2026-46702HIGH7.5Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.1, when SSH compression is enabl...
CVE-2026-46689HIGH8.7Kanidm is an identity management platform. Prior to version 1.9.3, a single unauthenticated GET to any /scim/v1/... endp...
CVE-2026-46679HIGH7.5libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 15.0.23, three cooperating omissions ...
CVE-2026-46673HIGH7.5Russh is a Rust SSH client & server library. Prior to version 0.60.3, CryptoVec used unchecked capacity growth, unchecke...
CVE-2026-46669HIGH7.5OpenVM is a performant and modular zkVM framework built for customization and extensibility. Prior to version 1.6.0, the...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now