2026 CVE Vulnerabilities
48,616 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9185 | HIGH | 7.5 | 0.4% | Jun 9, 2026 | The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versi... |
| CVE-2026-41851 | HIGH | 7.5 | 0.4% | Jun 9, 2026 | Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of S... |
| CVE-2026-41850 | HIGH | 7.5 | 0.4% | Jun 9, 2026 | Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic ... |
| CVE-2026-41849 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker c... |
| CVE-2026-41848 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provid... |
| CVE-2026-41842 | HIGH | 7.5 | 0.4% | Jun 9, 2026 | Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. ... |
| CVE-2026-41838 | HIGH | 7.5 | 0.2% | Jun 9, 2026 | IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible... |
| CVE-2026-41720 | HIGH | 7.4 | 0.3% | Jun 9, 2026 | Spring LDAP's DirContextAuthenticationStrategy implementations do not reject a bind request where a non-empty username i... |
| CVE-2026-41007 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings. ... |
| CVE-2026-41006 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media ty... |
| CVE-2026-40984 | HIGH | 7.5 | 0.8% | Jun 9, 2026 | In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (... |
| CVE-2026-40983 | HIGH | 7.5 | 0.5% | Jun 9, 2026 | In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (... |
| CVE-2026-26236 | HIGH | 7.5 | 0.3% | Jun 9, 2026 | A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vul... |
| CVE-2026-7556 | HIGH | 7.2 | 0.2% | Jun 9, 2026 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in... |
| CVE-2026-11618 | HIGH | 7.3 | 0.4% | Jun 9, 2026 | A vulnerability was determined in DTStack Taier up to 1.4.0. The affected element is the function preHandle of the file ... |
| CVE-2026-8795 | HIGH | 7.8 | 0.1% | Jun 9, 2026 | A YAML injection vulnerability exists in the Windows.Collectors.Remapping artifact of Rapid7 Velociraptor before version... |
| CVE-2026-44751 | HIGH | 7.1 | 0.2% | Jun 9, 2026 | Application server ABAP does not perform necessary authorization checks for an authenticated user allowing an attacker t... |
| CVE-2026-11700 | HIGH | 8.3 | 0.2% | Jun 9, 2026 | Use after free in Tracing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the ren... |
| CVE-2026-11699 | HIGH | 8.8 | 0.2% | Jun 9, 2026 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exp... |
| CVE-2026-11698 | HIGH | 8.8 | 0.2% | Jun 9, 2026 | Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exp... |
| CVE-2026-11694 | HIGH | 7.5 | 0.2% | Jun 9, 2026 | Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised t... |
| CVE-2026-11693 | HIGH | 8.1 | 0.2% | Jun 9, 2026 | Inappropriate implementation in Plugins in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compr... |
| CVE-2026-11692 | HIGH | 8.3 | 0.2% | Jun 9, 2026 | Use after free in Read Anything in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised t... |
| CVE-2026-11690 | HIGH | 7.5 | 0.2% | Jun 9, 2026 | Out of bounds read and write in Media in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had ... |
| CVE-2026-11689 | HIGH | 8.1 | 0.2% | Jun 9, 2026 | Insufficient policy enforcement in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now