2026 CVE Vulnerabilities

60,143 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-29509MEDIUM5.4Patool before 4.0.5 contains a path traversal vulnerability in the safe_extract() function in patoolib/programs/py_tarfi...
CVE-2026-54753MEDIUM5.9Nx is a monorepo solution for TypeScript and polyglot codebases. From 17.0.4 until 22.7.2 and 23.0.0-beta.2, the local H...
CVE-2026-48090MEDIUM5.9Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38...
CVE-2026-47220HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38...
CVE-2026-47205MEDIUM5.9Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.36.0 until 1.36.9, 1.37.5,...
CVE-2026-13372HIGH7.2Incorrect link resolution by display name in the custom PowerShell VPN editor in Devolutions Remote Desktop Manager 2026...
CVE-2026-56876HIGH8.6extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file contain...
CVE-2026-55448MEDIUM6.3mise manages dev tools like node, python, cmake, and terraform. From 2026.3.15 until 2026.6.4, mise loads github.credent...
CVE-2026-55441HIGH8.6mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config fil...
CVE-2026-54557MEDIUM5.5mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.1, the mise HTTP backend builds its inst...
CVE-2026-54341HIGH7.5Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.0, a crafted RESTORE payload ...
CVE-2026-48743HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,...
CVE-2026-48706HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9...
CVE-2026-48497HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,...
CVE-2026-48044HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.23.0 until 1.35.11, 1.36.7...
CVE-2026-48042HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,...
CVE-2026-47778MEDIUM4.4Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,...
CVE-2026-47775MEDIUM6.8Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3,...
CVE-2026-47692MEDIUM4.3Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9...
CVE-2026-47221HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.18.0 until 1.35.13, 1.36.9...
CVE-2026-47207MEDIUM6.5Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9...
CVE-2026-47206LOW2.3Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.9, Dragonfly has a RESP Proto...
CVE-2026-47204HIGH7.5Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.26.0 until 1.35.13, 1.36.9...
CVE-2026-33646CRITICAL9.6mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files ...
CVE-2026-57518HIGH8.8Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now