2026 CVE Vulnerabilities

57,064 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-29009CRITICAL9.8U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFI...
CVE-2026-29008HIGH8.7U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c...
CVE-2026-29007MEDIUM6.9U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability in tcp_rx_state_machine() (net/tcp.c) when CONFI...
CVE-2026-9074CRITICAL9.8IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulner...
CVE-2026-59880HIGH7.5Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, Immutable.Map and Immutable.S...
CVE-2026-59877HIGH7.5protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed opt...
CVE-2026-59876MEDIUM4.8protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 until 8.6.5, the protobufjs Text For...
CVE-2026-59875MEDIUM5.3node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX ...
CVE-2026-59874HIGH7.5node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar he...
CVE-2026-59873HIGH7.5node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds...
CVE-2026-59871HIGH7.5node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and lin...
CVE-2026-59870HIGH7.5js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.1, YAML11_SCHEMA support for the !!omap tag in src...
CVE-2026-59869HIGH7.5js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend ...
CVE-2026-59868HIGH7.5js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.0, when merge keys are enabled, js-yaml can spend ...
CVE-2026-59725HIGH7.5Socket.IO enables bidirectional and low-latency communication for every platform. From 4.1.0 before 6.6.7, Engine.IO pro...
CVE-2026-59724HIGH7.5Socket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO ser...
CVE-2026-59702CRITICAL9.3repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenticated ...
CVE-2026-59262HIGH7.1AFFiNE's histories GraphQL field fails to validate Doc.Read permission before exposing document edit history, allowing a...
CVE-2026-57439MEDIUM5CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.2.0, the Series Chart opera...
CVE-2026-55761MEDIUM5.9Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t...
CVE-2026-54344HIGH8.8ToolJet is an open-source low-code platform for building internal tools. Prior to 3.20.180, ToolJet's render preview dep...
CVE-2026-53951HIGH8.8Copier is a library and CLI app for rendering project templates. In versions 9.5.0 through 9.15.1, the `trust` setting's...
CVE-2026-49946Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-49945Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-49944Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now