2026 CVE Vulnerabilities

60,210 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-53538LOW3.7Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, QuerystringParser treated ; as a field sep...
CVE-2026-53537MEDIUM5.3Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Dispos...
CVE-2026-50556MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-50555MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-50269HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled inp...
CVE-2026-50184MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-50171MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-50170HIGH7.5Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-50169MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-50168HIGH8.2Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-49356LOW3.6Babel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an a...
CVE-2026-48712HIGH7.5protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.1 and 8.4.1, protobufjs could recu...
CVE-2026-46417MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-42127HIGH7.5The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attacke...
CVE-2026-12249CRITICAL9An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active Directory Certificate Servic...
CVE-2026-11994MEDIUM4.8Akaunting 3.1.21 contains an authenticated stored Cross-Site Scripting vulnerability in the report management workflow. ...
CVE-2026-11825Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r...
CVE-2026-10789CRITICAL9.6A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled...
CVE-2026-9610MEDIUM5.3IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality...
CVE-2026-9320HIGH7.5IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 a...
CVE-2026-9072CRITICAL9.8IBM WebSphere Application Server and IBM WebSphere Application Server Liberty - when using Intelligent Management with t...
CVE-2026-9071HIGH7.5IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 a...
CVE-2026-9006CRITICAL9.1IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy co...
CVE-2026-8934MEDIUM6.9A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud C...
CVE-2026-8858HIGH8.8IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to remote code execution an...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now