2026 CVE Vulnerabilities

48,558 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-22893HIGH7.2A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attack...
CVE-2026-45542HIGH7.1ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0...
CVE-2026-45541HIGH7.5ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0...
CVE-2026-45328HIGH8.8ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee componen...
CVE-2026-44634HIGH8.7SimpleBLE is a cross-platform library and bindings for Bluetooth Low Energy (BLE). Prior to version 0.14.0, there are mu...
CVE-2026-53674HIGH7.1BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when user...
CVE-2026-53673HIGH8.6BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authen...
CVE-2026-47838HIGH8.1SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead ...
CVE-2026-46545HIGH7.5Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to...
CVE-2026-46541HIGH7.5Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to...
CVE-2026-46518HIGH8.7OpenEMR is a free and open source electronic health records and medical practice management application. Prior to versio...
CVE-2026-46517HIGH7.8LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardc...
CVE-2026-46491HIGH8.6SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. Prior to versio...
CVE-2026-46432HIGH7.8LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, LMDep...
CVE-2026-45782HIGH8.9Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. From version 21.0 to before version 51.2, a guest can...
CVE-2026-44716HIGH7.5Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. From versi...
CVE-2026-41732HIGH8.1JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any pac...
CVE-2026-41731HIGH8.1JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a ...
CVE-2026-41729HIGH8.1Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (app...
CVE-2026-41728HIGH7.5Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to int...
CVE-2026-41717HIGH8.1Spring Data MongoDB contains a SpEL (Spring Expression Language) expression injection vulnerability. The issue occurs du...
CVE-2026-41716HIGH7.5Spring Data's internal property-lookup cache accepts and permanently retains attacker-supplied strings as cache keys, al...
CVE-2026-41695HIGH7.5Spring Data Commons applications may be vulnerable to denial of service through resource exhaustion when attacker-contro...
CVE-2026-40993HIGH7.2An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_assertin...
CVE-2026-40988HIGH7.5An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now