2026 CVE Vulnerabilities

60,251 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-53676HIGH8.6ThingsBoard contains a prototype pollution vulnerability which may lead to arbitrary code execution within a sandboxed c...
CVE-2026-50268LOW1.9Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-50267MEDIUM4.7Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-50202MEDIUM5.9Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-50201MEDIUM6.5Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-48759HIGH7.1TypeBot is a chatbot builder tool. Versions 3.15.2 and below have an Insecure Direct Object Reference vulnerability thro...
CVE-2026-45617HIGH7.5LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below,...
CVE-2026-45357HIGH7.5LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below,...
CVE-2026-44646MEDIUM5.3LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below,...
CVE-2026-44645MEDIUM6.5LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. In versions 10.25.7 and below,...
CVE-2026-44644MEDIUM6.1LiquidJS is a Shopify/GitHub Pages compatible template engine written in pure JavaScript. Versions 10.25.7 and below are...
CVE-2026-12568MEDIUM6.5The postman_download module uses the workspace name field from the Postman API to construct the local directory path wit...
CVE-2026-12567LOW2.2The github_workflows module constructs local directory paths from user-controlled repository names without validating fo...
CVE-2026-12566LOW3.1The docker_pull module uses the realm parameter from a Docker registry's WWW-Authenticate response header as the authent...
CVE-2026-12565MEDIUM5.3The unarchive internal module's archive extraction commands perform no code-level validation on extracted file paths, re...
CVE-2026-8050HIGH7.5In SignalRGB versions prior to 1.3.7.0, seven of the thirteen IOCTL handlers dereference the SystemBuffer pointer withou...
CVE-2026-8049MEDIUM5.3In SignalRGB versions prior to 1.3.7.0, the \\.\SignalIo device object is created without an explicit SDDL security desc...
CVE-2026-54386MEDIUM6.1marimo before 0.23.9 contains a reflected cross-site scripting vulnerability in the notebook page that allows unauthenti...
CVE-2026-50200HIGH7.5Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-50196HIGH7.5Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-50194HIGH8.2Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-48997HIGH7.1e107 is a content management system (CMS). Versions 2.3.5 and earlier contain a command injection vulnerability in the ...
CVE-2026-48991MEDIUM5.5XianYuLauncher is a Minecraft Java Edition launcher. In versions prior to 1.5.5, sensitive authentication artifacts coul...
CVE-2026-48990MEDIUM5.3joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar...
CVE-2026-48989HIGH8.9Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP m...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now