2026 CVE Vulnerabilities

48,616 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-9185HIGH7.5The 6Storage Rentals plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versi...
CVE-2026-41851HIGH7.5Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of S...
CVE-2026-41850HIGH7.5Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic ...
CVE-2026-41849HIGH7.5An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker c...
CVE-2026-41848HIGH7.5Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provid...
CVE-2026-41842HIGH7.5Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. ...
CVE-2026-41838HIGH7.5IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible...
CVE-2026-41720HIGH7.4Spring LDAP's DirContextAuthenticationStrategy implementations do not reject a bind request where a non-empty username i...
CVE-2026-41007HIGH7.5Spring HATEOAS maintains an unbounded static cache of StringLinkRelation instances keyed on attacker-supplied strings. ...
CVE-2026-41006HIGH7.5Spring HATEOAS's internal PropertyUtils.createObjectFromProperties method, used by the Collection+JSON and UBER media ty...
CVE-2026-40984HIGH7.5In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (...
CVE-2026-40983HIGH7.5In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (...
CVE-2026-26236HIGH7.5A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vul...
CVE-2026-7556HIGH7.2The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in...
CVE-2026-11618HIGH7.3A vulnerability was determined in DTStack Taier up to 1.4.0. The affected element is the function preHandle of the file ...
CVE-2026-8795HIGH7.8A YAML injection vulnerability exists in the Windows.Collectors.Remapping artifact of Rapid7 Velociraptor before version...
CVE-2026-44751HIGH7.1Application server ABAP does not perform necessary authorization checks for an authenticated user allowing an attacker t...
CVE-2026-11700HIGH8.3Use after free in Tracing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the ren...
CVE-2026-11699HIGH8.8Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exp...
CVE-2026-11698HIGH8.8Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to potentially exp...
CVE-2026-11694HIGH7.5Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised t...
CVE-2026-11693HIGH8.1Inappropriate implementation in Plugins in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compr...
CVE-2026-11692HIGH8.3Use after free in Read Anything in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised t...
CVE-2026-11690HIGH7.5Out of bounds read and write in Media in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had ...
CVE-2026-11689HIGH8.1Insufficient policy enforcement in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now