2026 CVE Vulnerabilities

57,060 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-8650HIGH7.5Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Tr...
CVE-2026-8649CRITICAL9.8Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Report...
CVE-2026-60104HIGH8Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to t...
CVE-2026-59948HIGH7Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an...
CVE-2026-59947MEDIUM4.7Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug ...
CVE-2026-59946MEDIUM6.1Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a Composer package bin entry containi...
CVE-2026-59939HIGH7.5httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression o...
CVE-2026-59936HIGH7.5pypdf is a free and open-source pure-python PDF library. Prior to 6.14.1, an attacker can craft a PDF with a page conten...
CVE-2026-59935HIGH7.5pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page conten...
CVE-2026-59822HIGH8.2LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Str...
CVE-2026-59821HIGH7.2LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's ...
CVE-2026-59820MEDIUM6.5LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.7-stable, LiteLLM Sk...
CVE-2026-59819MEDIUM4.9LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.83.10-stable, LiteLLM's...
CVE-2026-59807HIGH8.9Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and ex...
CVE-2026-59806HIGH7.4Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to re...
CVE-2026-59805HIGH7.1Gumroad before 2026.07.06.2 contains a broken access control vulnerability in the PurchasesController that allows authen...
CVE-2026-59804HIGH7.6Midscene Bridge Server through 1.10.3, fixed in commit 86f4118, contains a missing authentication and CORS misconfigurat...
CVE-2026-59803HIGH8.7rpcx through 1.9.3, fixed in commit 047aec1, contains a denial-of-service vulnerability in protocol.Message.Decode (prot...
CVE-2026-59802HIGH8.2PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_ur...
CVE-2026-58501MEDIUM5.9Zeep is a Python SOAP client. From 4.0.0 before 4.3.3, Settings.forbid_external is defined but not enforced when parsing...
CVE-2026-58254MEDIUM6.5NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2....
CVE-2026-58253HIGH8.8NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12....
CVE-2026-58252MEDIUM6.5NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12....
CVE-2026-58251MEDIUM6.5NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12....
CVE-2026-58250HIGH7.5NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.12.8 and 2....

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now