2026 CVE Vulnerabilities
48,558 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-22893 | HIGH | 7.2 | 1.0% | Jun 10, 2026 | A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack... |
| CVE-2026-45542 | HIGH | 7.1 | 0.3% | Jun 10, 2026 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0... |
| CVE-2026-45541 | HIGH | 7.5 | 0.4% | Jun 10, 2026 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0... |
| CVE-2026-45328 | HIGH | 8.8 | 0.1% | Jun 10, 2026 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee componen... |
| CVE-2026-44634 | HIGH | 8.7 | 0.3% | Jun 10, 2026 | SimpleBLE is a cross-platform library and bindings for Bluetooth Low Energy (BLE). Prior to version 0.14.0, there are mu... |
| CVE-2026-53674 | HIGH | 7.1 | 0.3% | Jun 10, 2026 | BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when user... |
| CVE-2026-53673 | HIGH | 8.6 | 0.4% | Jun 10, 2026 | BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authen... |
| CVE-2026-47838 | HIGH | 8.1 | 0.1% | Jun 10, 2026 | SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead ... |
| CVE-2026-46545 | HIGH | 7.5 | 0.3% | Jun 10, 2026 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to... |
| CVE-2026-46541 | HIGH | 7.5 | 0.3% | Jun 10, 2026 | Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to... |
| CVE-2026-46518 | HIGH | 8.7 | 0.2% | Jun 10, 2026 | OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio... |
| CVE-2026-46517 | HIGH | 7.8 | 0.1% | Jun 10, 2026 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardc... |
| CVE-2026-46491 | HIGH | 8.6 | 0.4% | Jun 10, 2026 | SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. Prior to versio... |
| CVE-2026-46432 | HIGH | 7.8 | 0.1% | Jun 10, 2026 | LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, LMDep... |
| CVE-2026-45782 | HIGH | 8.9 | 0.1% | Jun 10, 2026 | Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. From version 21.0 to before version 51.2, a guest can... |
| CVE-2026-44716 | HIGH | 7.5 | 0.4% | Jun 10, 2026 | Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. From versi... |
| CVE-2026-41732 | HIGH | 8.1 | 0.3% | Jun 10, 2026 | JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any pac... |
| CVE-2026-41731 | HIGH | 8.1 | 0.5% | Jun 10, 2026 | JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a ... |
| CVE-2026-41729 | HIGH | 8.1 | 0.4% | Jun 10, 2026 | Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (app... |
| CVE-2026-41728 | HIGH | 7.5 | 0.3% | Jun 10, 2026 | Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to int... |
| CVE-2026-41717 | HIGH | 8.1 | 0.3% | Jun 10, 2026 | Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue occurs du... |
| CVE-2026-41716 | HIGH | 7.5 | 0.4% | Jun 10, 2026 | Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, al... |
| CVE-2026-41695 | HIGH | 7.5 | 0.4% | Jun 10, 2026 | Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-contro... |
| CVE-2026-40993 | HIGH | 7.2 | 0.2% | Jun 10, 2026 | An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_assertin... |
| CVE-2026-40988 | HIGH | 7.5 | 0.3% | Jun 10, 2026 | An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now