2026 CVE Vulnerabilities

60,206 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48512HIGH7.5MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's JSON conversion ...
CVE-2026-48511HIGH7.5MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, ExpandoObjectFormatter.Deserialize po...
CVE-2026-48510HIGH7.5MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, when MessagePack-CSharp decompresses ...
CVE-2026-48509CRITICAL9.1MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless MessagePackInputFor...
CVE-2026-48506HIGH7.5MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.TrySkip() recursive...
CVE-2026-48505HIGH7.4Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5...
CVE-2026-48502HIGH7.5MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.ReadDateTime() can ...
CVE-2026-48500MEDIUM6.5Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5, ...
CVE-2026-48167MEDIUM6.4Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5...
CVE-2026-48166MEDIUM5.3Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5...
CVE-2026-48109HIGH8.2MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, A vulnerability exists in the optiona...
CVE-2026-48067MEDIUM6.5Filament is a collection of full-stack components for accelerated Laravel development. From filament/actions 4.0.0 until...
CVE-2026-44889MEDIUM6.1WebOb provides objects for HTTP requests and responses. Prior to 1.8.10, the normalization of the HTTP Location header d...
CVE-2026-44311MEDIUM6.1Fabric.js is a Javascript HTML5 canvas library. Prior to 7.4.0, a potential Cross-Site Scripting (XSS) vulnerability exi...
CVE-2026-55603HIGH7.5http-proxy-middleware is node.js http-proxy middleware. From 3.0.4 until 3.0.7 and 4.1.1, fixRequestBody() is the librar...
CVE-2026-55599MEDIUM5.8phpseclib is a PHP secure communications library. From 0.1.1 until 1.0.30, 2.0.55, and 3.0.54, when an application valid...
CVE-2026-54651MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.13.1, an attacker who uses this vulnerability can cr...
CVE-2026-54531MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can cr...
CVE-2026-54530MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can cr...
CVE-2026-49468CRITICAL9.8LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header par...
CVE-2026-49461MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can cr...
CVE-2026-49460LOW3.3pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can cr...
CVE-2026-47242MEDIUM5.8Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, wh...
CVE-2026-47241LOW2.1Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, se...
CVE-2026-47240MEDIUM5.8Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, se...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now