2026 CVE Vulnerabilities

64,785 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-47891CRITICAL9.8A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the ma...
CVE-2026-47890CRITICAL9.8Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fr...
CVE-2026-47884CRITICAL9.8Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping th...
CVE-2026-47875CRITICAL9.8Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deser...
CVE-2026-47864CRITICAL9.8SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream and...
CVE-2026-75340CRITICAL9.1The device metadata import interface /device/instance/{productId}/property-metadata/import of jetlinks community 2.11 is...
CVE-2026-75338CRITICAL9.8disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fet...
CVE-2026-75336CRITICAL9.8Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update....
CVE-2026-75332CRITICAL9.1Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download().
CVE-2026-75330CRITICAL9.8The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerab...
CVE-2026-65956CRITICAL10KubePi is a Kubernetes multi-cluster management panel. In versions up to and including 1.6.15, the SSO configuration API...
CVE-2026-75329CRITICAL9.8The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanis...
CVE-2026-65646CRITICAL9.9Improper neutralization of special elements in in Plesk's DNS zone management functionality allows remote authenticated ...
CVE-2026-65641CRITICAL9.3A vulnerability allowing an unauthenticated network attacker to coerce SMB authentication from the service account.
CVE-2026-75414CRITICAL9.8In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which l...
CVE-2026-75411CRITICAL9.8JeecgBoot v3.9.2 is vulnerable to Remote command execution. The CodeNode component of the AI Flow module supports Groovy...
CVE-2026-52103CRITICAL9.8A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before...
CVE-2026-75334CRITICAL9.8The report module in the backend of smart-web2 v1.3.1 is vulnerable to arbitrary SQL execution. The sqlResource.sql para...
CVE-2026-75327CRITICAL9.8In DocSys-master V2.02.85, the uploadMarkdownPic interface in src/com/DocSystem/controller/DocController.java has an arb...
CVE-2026-68000CRITICAL9.8The front-end interface /cms/category/list of MCMS <=6.2.0 is vulnerable to SQL injection. The size parameter is directl...
CVE-2026-60004CRITICAL9.8Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
CVE-2026-26448CRITICAL9.8Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection,...
CVE-2026-75325CRITICAL9.8DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' param...
CVE-2026-70419CRITICAL9.1Dell Cloud Disaster Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an...
CVE-2026-51106CRITICAL9.3An issue in TokTok qTox v1.18.4 allows a local attacker to cause a denial of service via the src/persistence/serialize.c...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now