2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47891 | CRITICAL | 9.8 | 0.3% | Aug 27, 2026 | A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the ma... |
| CVE-2026-47890 | CRITICAL | 9.8 | 0.3% | Aug 27, 2026 | Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fr... |
| CVE-2026-47884 | CRITICAL | 9.8 | 0.4% | Aug 27, 2026 | Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping th... |
| CVE-2026-47875 | CRITICAL | 9.8 | 0.2% | Aug 27, 2026 | Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deser... |
| CVE-2026-47864 | CRITICAL | 9.8 | 3.4% | Aug 27, 2026 | SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream and... |
| CVE-2026-75340 | CRITICAL | 9.1 | 0.2% | Aug 26, 2026 | The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is... |
| CVE-2026-75338 | CRITICAL | 9.8 | 0.3% | Aug 26, 2026 | disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fet... |
| CVE-2026-75336 | CRITICAL | 9.8 | 0.3% | Aug 26, 2026 | Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.... |
| CVE-2026-75332 | CRITICAL | 9.1 | 0.3% | Aug 26, 2026 | Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download(). |
| CVE-2026-75330 | CRITICAL | 9.8 | 0.3% | Aug 26, 2026 | The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerab... |
| CVE-2026-65956 | CRITICAL | 10 | 0.4% | Aug 26, 2026 | KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API... |
| CVE-2026-75329 | CRITICAL | 9.8 | 0.3% | Aug 26, 2026 | The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanis... |
| CVE-2026-65646 | CRITICAL | 9.9 | 0.3% | Aug 26, 2026 | Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated ... |
| CVE-2026-65641 | CRITICAL | 9.3 | 0.5% | Aug 26, 2026 | A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account. |
| CVE-2026-75414 | CRITICAL | 9.8 | 0.5% | Aug 26, 2026 | In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which l... |
| CVE-2026-75411 | CRITICAL | 9.8 | 0.2% | Aug 26, 2026 | JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy... |
| CVE-2026-52103 | CRITICAL | 9.8 | 0.6% | Aug 26, 2026 | A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before... |
| CVE-2026-75334 | CRITICAL | 9.8 | 0.2% | Aug 26, 2026 | The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution. The sqlResource.sql para... |
| CVE-2026-75327 | CRITICAL | 9.8 | 0.1% | Aug 26, 2026 | In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arb... |
| CVE-2026-68000 | CRITICAL | 9.8 | 0.2% | Aug 26, 2026 | The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The size parameter is directl... |
| CVE-2026-60004 | CRITICAL | 9.8 | — | Aug 26, 2026 | Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. |
| CVE-2026-26448 | CRITICAL | 9.8 | 0.4% | Aug 26, 2026 | Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection,... |
| CVE-2026-75325 | CRITICAL | 9.8 | 0.3% | Aug 26, 2026 | DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' param... |
| CVE-2026-70419 | CRITICAL | 9.1 | 2.2% | Aug 26, 2026 | Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an... |
| CVE-2026-51106 | CRITICAL | 9.3 | 0.2% | Aug 26, 2026 | An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.c... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now