2026 CVE Vulnerabilities

65,293 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-101910MEDIUM6.9ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.2.0 until 10.5.1, th...
CVE-2026-101909HIGH8.3Axios is a promise-based HTTP client for the browser and Node.js. From 0.28.0 until 0.34.0 and 1.15.1 until 1.20.0, ToFo...
CVE-2026-101908MEDIUM6.9Axios is a promise-based HTTP client for the browser and Node.js. From 1.7.0 until 1.20.0, the fetch adapter constructs ...
CVE-2026-101907HIGH7Axios is a promise-based HTTP client for the browser and Node.js. From 1.17.0 until 1.20.0, the fetch adapter bypasses t...
CVE-2026-101906HIGH8.2Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.0 until 1.20.0, Axios shouldBypassProxy appl...
CVE-2026-101905HIGH7.6Axios is a promise-based HTTP client for the browser and Node.js. From 1.15.2 until 1.20.0, the Node HTTP adapter in lib...
CVE-2026-101904MEDIUM6.9Axios is a promise-based HTTP client for the browser and Node.js. From 1.0.0 until 1.20.0, the dispatchRequest function ...
CVE-2026-101903HIGH8.2Axios is a promise-based HTTP client for the browser and Node.js. From 1.16.1 until 1.20.0, the RFC 2397 regular express...
CVE-2026-101902MEDIUM6.9Axios is a promise-based HTTP client for the browser and Node.js. From 0.27.2 until 0.34.0 and 1.20.0, Axios default-ins...
CVE-2026-101901HIGH8.2Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Http2Sessions does not insta...
CVE-2026-101900MEDIUM6.9Axios is a promise-based HTTP client for the browser and Node.js. From 1.12.0 until 1.20.0, ResolveConfig reads inherite...
CVE-2026-101898HIGH7Axios is a promise-based HTTP client for the browser and Node.js. From 1.13.0 until 1.20.0, Axios HTTP/2 request setup d...
CVE-2026-101102MEDIUM6.3A vulnerability was found in deepseek-ai deepseek-harness up to 0.1.0-rc.7. Impacted is the function run_code of the com...
CVE-2026-101101MEDIUM4.3A vulnerability has been found in ag-ui-protocol ag-ui up to 2026-09-07. This issue affects the function JSON.parse of t...
CVE-2026-101100MEDIUM5.4A flaw has been found in ag-ui-protocol ag-ui up to 2026-09-07. This vulnerability affects the function FilterToolCallsM...
CVE-2026-101099MEDIUM4.3A vulnerability was detected in ag-ui-protocol ag-ui up to 2026-09-23. This affects an unknown part of the file SseParse...
CVE-2026-88816——DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in FetchHashKeyName. fetchrow_hashref us...
CVE-2026-88815——DBI versions before 1.654 for Perl incorrectly treat numeric values as strings in sql_type_cast_svpv. When casting to S...
CVE-2026-87969HIGH8.6An OS command injection vulnerability in the WatchGuard AP diagnostic CLI allows an authenticated administrator to execu...
CVE-2026-87114HIGH7.1A flaw was found in kube-compare. When processing a 'container://' reference path, the tool incorrectly executes an untr...
CVE-2026-86102CRITICAL9.3An OS command injection vulnerability in the WatchGuard AP internal API service allows an attacker with network access t...
CVE-2026-85644——XS::Parse::Infix versions from 0.40 through 0.49 for Perl treat a number as an array reference. The wrapper function XS...
CVE-2026-58464——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-58463——Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-55096HIGH7.1fast-mcp-telegram is a Telegram MCP Server. Prior to version 30.1, the send_message/send_message_to_phone MCP tools acce...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now