2026 CVE Vulnerabilities
60,210 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49460 | LOW | 3.3 | 0.1% | Jun 22, 2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can cr... |
| CVE-2026-47242 | MEDIUM | 5.8 | 0.1% | Jun 22, 2026 | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, wh... |
| CVE-2026-47241 | LOW | 2.1 | 0.2% | Jun 22, 2026 | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, se... |
| CVE-2026-47240 | MEDIUM | 5.8 | 0.5% | Jun 22, 2026 | Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, se... |
| CVE-2026-45034 | CRITICAL | 9.2 | 0.4% | Jun 22, 2026 | PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patc... |
| CVE-2026-44727 | MEDIUM | 5.4 | 0.4% | Jun 22, 2026 | Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server... |
| CVE-2026-41479 | MEDIUM | 5.4 | 0.2% | Jun 22, 2026 | Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.... |
| CVE-2026-39904 | HIGH | 7.1 | 0.2% | Jun 22, 2026 | Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to ... |
| CVE-2026-48931 | LOW | 3.7 | 0.4% | Jun 22, 2026 | A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent th... |
| CVE-2026-44274 | HIGH | 7.8 | 0.1% | Jun 22, 2026 | Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Before File Access vul... |
| CVE-2026-44273 | MEDIUM | 4.4 | 0.1% | Jun 22, 2026 | Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials vulnerability. A high... |
| CVE-2026-44272 | HIGH | 8.8 | 0.2% | Jun 22, 2026 | Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements use... |
| CVE-2026-44271 | HIGH | 8.8 | 0.2% | Jun 22, 2026 | Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements use... |
| CVE-2026-10852 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the... |
| CVE-2026-55443 | MEDIUM | 5.5 | 0.2% | Jun 22, 2026 | LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components ... |
| CVE-2026-54300 | MEDIUM | 5.3 | 0.2% | Jun 22, 2026 | @astrojs/netlify is an adapter that allows Astro to deploy your hybrid or server rendered site to Netlify. Prior to 7.0.... |
| CVE-2026-54299 | HIGH | 7.5 | 0.2% | Jun 22, 2026 | Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using export const p... |
| CVE-2026-54298 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Astro is a web framework. Prior to 6.4.6, the spreadAttributes function in Astro's server-side rendering pipeline iterat... |
| CVE-2026-54293 | HIGH | 7.5 | 0.6% | Jun 22, 2026 | NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a... |
| CVE-2026-54288 | MEDIUM | 6.5 | 0.1% | Jun 22, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, the Body Limit M... |
| CVE-2026-53779 | HIGH | 8.7 | 0.4% | Jun 22, 2026 | WebP Server Go through 0.14.4 contains a path traversal vulnerability on Windows that allows unauthenticated attackers t... |
| CVE-2026-53778 | — | — | — | Jun 22, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-53663 | LOW | 3.1 | 0.1% | Jun 22, 2026 | React Router is a router for React. From 7.12.0 until 7.15.1, certain CSRF checks in React Router v7 Framework Mode were... |
| CVE-2026-50146 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot content i... |
| CVE-2026-11834 | HIGH | 8.7 | 0.4% | Jun 22, 2026 | A command injection vulnerability has been identified in the DHCP option processing logic in multiple TP-Link router mod... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now