2026 CVE Vulnerabilities
60,149 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-50573 | HIGH | 8.1 | 0.1% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` in non-frozen mode can accept new remote package ... |
| CVE-2026-50021 | HIGH | 8.1 | 0.1% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's tarball extraction worker skips integrity verification wh... |
| CVE-2026-50017 | MEDIUM | 6.5 | 0.3% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm can send user-level unscoped npm authentication credentials... |
| CVE-2026-50016 | HIGH | 8.8 | 0.3% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package ... |
| CVE-2026-50015 | HIGH | 7.3 | 0.3% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's patch application pipeline (@pnpm/patch-package) performs... |
| CVE-2026-50014 | HIGH | 7.3 | 0.2% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm passes the lockfile-controlled git resolution.commit value ... |
| CVE-2026-49839 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into inval... |
| CVE-2026-48995 | HIGH | 7.5 | 0.1% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarbal... |
| CVE-2026-47770 | MEDIUM | 5.5 | 0.1% | Jun 25, 2026 | jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operato... |
| CVE-2026-11999 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_... |
| CVE-2026-9800 | HIGH | 8.1 | 0.6% | Jun 25, 2026 | A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorizati... |
| CVE-2026-9799 | MEDIUM | 4.6 | 0.2% | Jun 25, 2026 | A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permissio... |
| CVE-2026-9705 | MEDIUM | 6.5 | 0.3% | Jun 25, 2026 | A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registrati... |
| CVE-2026-9099 | HIGH | 7.7 | 0.3% | Jun 25, 2026 | A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin RE... |
| CVE-2026-9086 | HIGH | 7.3 | 0.4% | Jun 25, 2026 | A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` ... |
| CVE-2026-9083 | MEDIUM | 4.9 | 0.5% | Jun 25, 2026 | A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submi... |
| CVE-2026-56123 | CRITICAL | 9.8 | 0.3% | Jun 25, 2026 | socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5... |
| CVE-2026-55439 | MEDIUM | 5.5 | 0.3% | Jun 25, 2026 | Halo is an open source website building tool. Prior to 2.24.3, a path traversal vulnerability in the backup download end... |
| CVE-2026-55413 | CRITICAL | 9.4 | 0.3% | Jun 25, 2026 | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI ... |
| CVE-2026-55412 | HIGH | 8.3 | 0.2% | Jun 25, 2026 | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI ... |
| CVE-2026-55411 | MEDIUM | 6.8 | 0.1% | Jun 25, 2026 | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI ... |
| CVE-2026-55092 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image... |
| CVE-2026-54573 | MEDIUM | 5.3 | 0.3% | Jun 25, 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.8.0, the AuthenticationHelper.canAccess fun... |
| CVE-2026-54448 | MEDIUM | 6.5 | 0.3% | Jun 25, 2026 | Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker read... |
| CVE-2026-54040 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/auth/2fa/b... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now