2026 CVE Vulnerabilities

61,320 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44206MEDIUM6.9Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, DB Schema Enumeration is possi...
CVE-2026-40677HIGH7.7The use of insecure HTTP transport within AMD optional tools could allow an attacker to conduct a man-in-the-middle atta...
CVE-2026-8694MEDIUM5.3Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attack...
CVE-2026-7368HIGH8.6The Yarbo cloud does not enforce per-device or per-user authorization. Any client possessing valid credentials, whether ...
CVE-2026-6853CRITICAL9.8Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe Businesses Industry ...
CVE-2026-6211HIGH8.7Unrestricted upload of file with dangerous type vulnerability in Global IT Informatics Services Inc. WEOLL allows Access...
CVE-2026-54133CRITICAL9.8jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON doc...
CVE-2026-53787CRITICAL9.8Amasty Order Attributes for Magento 2 before version 4.0.0 contains an unauthenticated arbitrary file upload vulnerabili...
CVE-2026-53722MEDIUM5.4Nuxt is an open-source web development framework for Vue.js. Prior to versions 3.21.7 and 4.4.7, <NuxtLink> did not vali...
CVE-2026-53721HIGH8.2Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4...
CVE-2026-47739MEDIUM6.9Frappe is a full-stack web application framework. Prior to versions 15.106.0 and 16.16.0, stored XSS in Note was possibl...
CVE-2026-47244MEDIUM5.3Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-47210CRITICAL9.8vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, a sandbox escape vulnerability in vm2 allows arbi...
CVE-2026-47209HIGH8.6vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the BaseHandler.set trap in bridge.js (line 1231)...
CVE-2026-47208CRITICAL10vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability...
CVE-2026-47141MEDIUM6.9vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM exposes some process-wide observability bu...
CVE-2026-47140CRITICAL10vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM blocks several dangerous Node.js builtins ...
CVE-2026-47139HIGH8.6vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, NodeVM supports excluding public network builtins...
CVE-2026-47137CRITICAL10vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, the fix for GHSA-8hg8-63c5-gwmx (CVE-2023-37903) ...
CVE-2026-47135HIGH8.7vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, Symbol.for override in setup-sandbox.js only inte...
CVE-2026-47131CRITICAL10vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, by combining Buffer.call.call({}.__lookupGetter__...
CVE-2026-46340HIGH7.5Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport...
CVE-2026-45674CRITICAL10Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-45673MEDIUM6.8Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...
CVE-2026-45536MEDIUM4Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Fina...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now