2026 CVE Vulnerabilities
60,143 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-29509 | MEDIUM | 5.4 | 0.3% | Jun 26, 2026 | Patool before 4.0.5 contains a path traversal vulnerability in the safe_extract() function in patoolib/programs/py_tarfi... |
| CVE-2026-54753 | MEDIUM | 5.9 | — | Jun 26, 2026 | Nx is a monorepo solution for TypeScript and polyglot codebases. From 17.0.4 until 22.7.2 and 23.0.0-beta.2, the local H... |
| CVE-2026-48090 | MEDIUM | 5.9 | 0.6% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38... |
| CVE-2026-47220 | HIGH | 7.5 | 0.7% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38... |
| CVE-2026-47205 | MEDIUM | 5.9 | 0.4% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.36.0 until 1.36.9, 1.37.5,... |
| CVE-2026-13372 | HIGH | 7.2 | 0.3% | Jun 26, 2026 | Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026... |
| CVE-2026-56876 | HIGH | 8.6 | 0.3% | Jun 26, 2026 | extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file contain... |
| CVE-2026-55448 | MEDIUM | 6.3 | — | Jun 26, 2026 | mise manages dev tools like node, python, cmake, and terraform. From 2026.3.15 until 2026.6.4, mise loads github.credent... |
| CVE-2026-55441 | HIGH | 8.6 | — | Jun 26, 2026 | mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config fil... |
| CVE-2026-54557 | MEDIUM | 5.5 | — | Jun 26, 2026 | mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.1, the mise HTTP backend builds its inst... |
| CVE-2026-54341 | HIGH | 7.5 | — | Jun 26, 2026 | Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.0, a crafted RESTORE payload ... |
| CVE-2026-48743 | HIGH | 7.5 | 0.3% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,... |
| CVE-2026-48706 | HIGH | 7.5 | 0.6% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9... |
| CVE-2026-48497 | HIGH | 7.5 | 0.4% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,... |
| CVE-2026-48044 | HIGH | 7.5 | 0.5% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.23.0 until 1.35.11, 1.36.7... |
| CVE-2026-48042 | HIGH | 7.5 | 0.5% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,... |
| CVE-2026-47778 | MEDIUM | 4.4 | 0.2% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,... |
| CVE-2026-47775 | MEDIUM | 6.8 | 0.2% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,... |
| CVE-2026-47692 | MEDIUM | 4.3 | 0.2% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9... |
| CVE-2026-47221 | HIGH | 7.5 | 0.4% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.18.0 until 1.35.13, 1.36.9... |
| CVE-2026-47207 | MEDIUM | 6.5 | 0.4% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9... |
| CVE-2026-47206 | LOW | 2.3 | — | Jun 26, 2026 | Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.9, Dragonfly has a RESP Proto... |
| CVE-2026-47204 | HIGH | 7.5 | 0.4% | Jun 26, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.26.0 until 1.35.13, 1.36.9... |
| CVE-2026-33646 | CRITICAL | 9.6 | 0.7% | Jun 26, 2026 | mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files ... |
| CVE-2026-57518 | HIGH | 8.8 | 0.5% | Jun 26, 2026 | Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now