2026 CVE Vulnerabilities
60,210 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56109 | HIGH | 7 | 0.1% | Jun 22, 2026 | The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def()... |
| CVE-2026-55602 | HIGH | 8.6 | 0.4% | Jun 22, 2026 | http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middlewar... |
| CVE-2026-55388 | HIGH | 8.1 | 0.3% | Jun 22, 2026 | piscina is a node.js worker pool implementation. Prior to 6.0.0-rc.2, 5.2.0, and 4.9.3, piscina's constructor and run() ... |
| CVE-2026-54290 | HIGH | 7.1 | 0.2% | Jun 22, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, with credentials... |
| CVE-2026-54289 | MEDIUM | 4.8 | 0.1% | Jun 22, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda@Ed... |
| CVE-2026-54287 | MEDIUM | 5.3 | 0.2% | Jun 22, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda, t... |
| CVE-2026-54286 | MEDIUM | 5.9 | 0.3% | Jun 22, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts... |
| CVE-2026-54285 | MEDIUM | 5.3 | 0.3% | Jun 22, 2026 | opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 2.8.0, W3CBaggagePropagator.extract() in @opentelemetr... |
| CVE-2026-54283 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_par... |
| CVE-2026-54282 | MEDIUM | 5.3 | 0.2% | Jun 22, 2026 | Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being u... |
| CVE-2026-54280 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are n... |
| CVE-2026-54279 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that ... |
| CVE-2026-54278 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is po... |
| CVE-2026-54277 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypas... |
| CVE-2026-54276 | MEDIUM | 6.1 | 0.3% | Jun 22, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware ca... |
| CVE-2026-54275 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS... |
| CVE-2026-54274 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends la... |
| CVE-2026-54273 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on... |
| CVE-2026-54271 | HIGH | 8.2 | 0.2% | Jun 22, 2026 | protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.3.2 and 2.5.0, a previous fix for unsafe name hand... |
| CVE-2026-54270 | MEDIUM | 5.3 | 0.3% | Jun 22, 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 to 8.4.2, protobufjs preserved unkno... |
| CVE-2026-54269 | MEDIUM | 5.3 | 0.2% | Jun 22, 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 8.6.0 and 7.6.3, protobufjs accepted c... |
| CVE-2026-53632 | MEDIUM | 5.5 | 0.3% | Jun 22, 2026 | launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NP... |
| CVE-2026-53571 | HIGH | 7.5 | 0.4% | Jun 22, 2026 | Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are s... |
| CVE-2026-53540 | LOW | 3.7 | 0.2% | Jun 22, 2026 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-... |
| CVE-2026-53539 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlenc... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now