2026 CVE Vulnerabilities

60,210 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-49460LOW3.3pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can cr...
CVE-2026-47242MEDIUM5.8Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, wh...
CVE-2026-47241LOW2.1Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, se...
CVE-2026-47240MEDIUM5.8Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, se...
CVE-2026-45034CRITICAL9.2PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patc...
CVE-2026-44727MEDIUM5.4Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server...
CVE-2026-41479MEDIUM5.4Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2....
CVE-2026-39904HIGH7.1Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to ...
CVE-2026-48931LOW3.7A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent th...
CVE-2026-44274HIGH7.8Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Before File Access vul...
CVE-2026-44273MEDIUM4.4Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials vulnerability. A high...
CVE-2026-44272HIGH8.8Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements use...
CVE-2026-44271HIGH8.8Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements use...
CVE-2026-10852HIGH7.5IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the...
CVE-2026-55443MEDIUM5.5LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components ...
CVE-2026-54300MEDIUM5.3@astrojs/netlify is an adapter that allows Astro to deploy your hybrid or server rendered site to Netlify. Prior to 7.0....
CVE-2026-54299HIGH7.5Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using export const p...
CVE-2026-54298MEDIUM6.1Astro is a web framework. Prior to 6.4.6, the spreadAttributes function in Astro's server-side rendering pipeline iterat...
CVE-2026-54293HIGH7.5NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a...
CVE-2026-54288MEDIUM6.5Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, the Body Limit M...
CVE-2026-53779HIGH8.7WebP Server Go through 0.14.4 contains a path traversal vulnerability on Windows that allows unauthenticated attackers t...
CVE-2026-53778Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-53663LOW3.1React Router is a router for React. From 7.12.0 until 7.15.1, certain CSRF checks in React Router v7 Framework Mode were...
CVE-2026-50146MEDIUM6.1Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot content i...
CVE-2026-11834HIGH8.7A command injection vulnerability has been identified in the DHCP option processing logic in multiple TP-Link router mod...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now