2026 CVE Vulnerabilities
57,064 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-50812 | MEDIUM | 5.5 | 0.1% | Jul 8, 2026 | A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807... |
| CVE-2026-14362 | MEDIUM | 4.9 | 0.3% | Jul 8, 2026 | HashiCorp memberlist before version 0.6.0 is vulnerable to a denial-of-service issue in its push/pull state handling tha... |
| CVE-2026-60102 | HIGH | 8.8 | 1.8% | Jul 8, 2026 | Horde Virtual File System (VFS) API before 3.0.1 contains an OS command injection vulnerability in the Horde_Vfs_Smb dri... |
| CVE-2026-59930 | MEDIUM | 4.3 | 0.1% | Jul 8, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the toc plugin and TableOfContents direc... |
| CVE-2026-59929 | MEDIUM | 6.1 | 0.2% | Jul 8, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the safe_url filter in src/mistune/rende... |
| CVE-2026-59928 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repe... |
| CVE-2026-59927 | MEDIUM | 5.3 | 0.3% | Jul 8, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/dir... |
| CVE-2026-59926 | MEDIUM | 6.1 | 0.3% | Jul 8, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/direc... |
| CVE-2026-59925 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-ast... |
| CVE-2026-59924 | MEDIUM | 5.9 | 0.3% | Jul 8, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes use... |
| CVE-2026-59923 | MEDIUM | 6.1 | 0.2% | Jul 8, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block p... |
| CVE-2026-59922 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or c... |
| CVE-2026-59897 | MEDIUM | 5.3 | 0.1% | Jul 8, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS... |
| CVE-2026-59896 | MEDIUM | 6.5 | 0.2% | Jul 8, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/j... |
| CVE-2026-59895 | MEDIUM | 6.1 | 0.2% | Jul 8, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in... |
| CVE-2026-59892 | HIGH | 7.5 | 0.4% | Jul 8, 2026 | OpenTelemetry JavaScript is the OpenTelemetry JavaScript client. Prior to 2.9.0, @opentelemetry/propagator-jaeger decode... |
| CVE-2026-59890 | MEDIUM | 6.1 | 0.3% | Jul 8, 2026 | setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to ... |
| CVE-2026-59887 | HIGH | 7.5 | 0.6% | Jul 8, 2026 | linkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used b... |
| CVE-2026-59883 | MEDIUM | 6.1 | 0.1% | Jul 8, 2026 | Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bar... |
| CVE-2026-59882 | MEDIUM | 6.5 | 0.2% | Jul 8, 2026 | guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not ... |
| CVE-2026-59879 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#... |
| CVE-2026-59731 | HIGH | 8.2 | 0.3% | Jul 8, 2026 | Astro is a web framework for content-driven websites. Version 6.4.7 performs authorization decisions on a partially deco... |
| CVE-2026-59261 | MEDIUM | 6.5 | 0.1% | Jul 8, 2026 | OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provide... |
| CVE-2026-42505 | MEDIUM | 5.3 | 0.4% | Jul 8, 2026 | Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of... |
| CVE-2026-39822 | HIGH | 7.8 | 0.2% | Jul 8, 2026 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now