2026 CVE Vulnerabilities

57,064 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-58253HIGH8.8NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12....
CVE-2026-58252MEDIUM6.5NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12....
CVE-2026-58251MEDIUM6.5NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12....
CVE-2026-58250HIGH7.5NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.12.8 and 2....
CVE-2026-58214MEDIUM4.3NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2....
CVE-2026-58213HIGH7.1NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.1 and 2....
CVE-2026-58212Rejected reason: Further research determined the issue is not a vulnerability based on CNA Rule 4.1.12 The act of updati...
CVE-2026-58210HIGH7.5NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2....
CVE-2026-58209MEDIUM4.3NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2....
CVE-2026-55760HIGH7.5Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.2, applications that pass us...
CVE-2026-55575HIGH8.2LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.1, the pop array filt...
CVE-2026-55404HIGH8.8yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the --write-link, --write-url-link, a...
CVE-2026-53624MEDIUM4.8Fiber is an Express inspired web framework written in Go. Prior to 3.4.0, the helmet middleware in middleware/helmet/hel...
CVE-2026-45045MEDIUM5.3Fiber is an Express inspired web framework written in Go. Prior to 3.3.0 and 2.52.14, the BalancerForward proxy helper i...
CVE-2026-44512MEDIUM5.5Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.9.0 before 1.22.0,...
CVE-2026-44332MEDIUM5.3Fiber is an Express inspired web framework written in Go. Prior to 3.3.0, the default Authorizer function in the BasicAu...
CVE-2026-36028MEDIUM6.8A protection mechanism failure in the Code 27 Companion Hub allows an attacker with physical access to completely bypass...
CVE-2026-36027MEDIUM6.8An issue in Code27 Companion Hub SQ3A.220705.003.A1 allows a physically proximate attacker to execute arbitrary code via...
CVE-2026-15154MEDIUM6.5A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Ex...
CVE-2026-14891HIGH8.7HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job s...
CVE-2026-14373HIGH7.7HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host ...
CVE-2026-14361MEDIUM4.7The consul-template library before version 0.42.1 is vulnerable to a path redirection issue in the writeToFile template ...
CVE-2026-59938MEDIUM5.3pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with declared imag...
CVE-2026-59937HIGH7.5pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with repeated malf...
CVE-2026-50813MEDIUM6.1An issue in SQLite before Fossil check-in 869a51ae84df allows a local attacker to obtain sensitive information via the S...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now