2026 CVE Vulnerabilities

60,340 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-12568MEDIUM6.5The postman_download module uses the workspace name field from the Postman API to construct the local directory path wit...
CVE-2026-12567LOW2.2The github_workflows module constructs local directory paths from user-controlled repository names without validating fo...
CVE-2026-12566LOW3.1The docker_pull module uses the realm parameter from a Docker registry's WWW-Authenticate response header as the authent...
CVE-2026-12565MEDIUM5.3The unarchive internal module's archive extraction commands perform no code-level validation on extracted file paths, re...
CVE-2026-8050HIGH7.5In SignalRGB versions prior to 1.3.7.0, seven of the thirteen IOCTL handlers dereference the SystemBuffer pointer withou...
CVE-2026-8049MEDIUM5.3In SignalRGB versions prior to 1.3.7.0, the \\.\SignalIo device object is created without an explicit SDDL security desc...
CVE-2026-54386MEDIUM6.1marimo before 0.23.9 contains a reflected cross-site scripting vulnerability in the notebook page that allows unauthenti...
CVE-2026-50200HIGH7.5Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-50196HIGH7.5Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-50194HIGH8.2Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applicati...
CVE-2026-48997HIGH7.1e107 is a content management system (CMS). Versions 2.3.5 and earlier contain a command injection vulnerability in the ...
CVE-2026-48991MEDIUM5.5XianYuLauncher is a Minecraft Java Edition launcher. In versions prior to 1.5.5, sensitive authentication artifacts coul...
CVE-2026-48990MEDIUM5.3joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar...
CVE-2026-48989HIGH8.9Windows-MCP is an open-source project that integrates AI agents with Windows. In versions prior to 0.7.5, certain HTTP m...
CVE-2026-48820MEDIUM6.3CakePHP is a rapid development framework for PHP. In versions 4.5.11 and earlier, 4.6.0 through 4.6.3, 5.0.0 through 5.1...
CVE-2026-12530HIGH8.4Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK vers...
CVE-2026-49133HIGH7.1Typemill before 2.24.0 contains a path traversal vulnerability that allows authenticated attackers with Author-level pri...
CVE-2026-48988MEDIUM5.3markdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: ...
CVE-2026-48979HIGH7.5PHP Standard Library (PSL) is set of APIs covering async, collections, networking, I/O, cryptography, terminal UI, etc. ...
CVE-2026-48821MEDIUM5.8Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a DOM-based Cross-Site Scripting (XSS) vuln...
CVE-2026-55202HIGH8.8Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection,...
CVE-2026-55201HIGH7.4Evil-WinRM through 3.9, fixed in commit 6ecd570, contains a path traversal vulnerability in the download_dir() function ...
CVE-2026-55200HIGH8.3libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() t...
CVE-2026-55199HIGH7.5libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SS...
CVE-2026-54388CRITICAL9.3Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length headers w...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now