2026 CVE Vulnerabilities

61,327 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-48546HIGH8.5KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by expl...
CVE-2026-47157MEDIUM6.5aiograpi is an asynchronous Instagram API for Python. aiograpi versions before 0.9.10 accepted server-supplied signup ch...
CVE-2026-46698MEDIUM5.3Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.9, Fediverse Embeds registered the unau...
CVE-2026-46697HIGH7.5Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unaut...
CVE-2026-3329HIGH7.5A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype N...
CVE-2026-11986MEDIUM4.9A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabi...
CVE-2026-49982HIGH8.2tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects ...
CVE-2026-44705HIGH8.2tmp is a temporary file and directory creator for node.js. Prior to 0.2.6, the tmp npm package contains a path traversal...
CVE-2026-44496HIGH7.5Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and befor...
CVE-2026-44495HIGH7.7Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contain...
CVE-2026-44494HIGH8.7Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vuln...
CVE-2026-44492HIGH8.6Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise I...
CVE-2026-44490HIGH8.2Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-sid...
CVE-2026-44489MEDIUM5.3Axios is a promise based HTTP client for the browser and Node.js. From 1.15.2 to before 1.16.0, nested objects created b...
CVE-2026-44488HIGH7.5Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce co...
CVE-2026-44487HIGH7.5Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapt...
CVE-2026-44486HIGH7.5Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapte...
CVE-2026-11945HIGH7.5PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON docume...
CVE-2026-9648CRITICAL9.1The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certi...
CVE-2026-7870HIGH8.8IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malici...
CVE-2026-7787HIGH8.1IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypass...
CVE-2026-53777HIGH8.6Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary co...
CVE-2026-4096MEDIUM6.1IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by th...
CVE-2026-3341MEDIUM5.4IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allo...
CVE-2026-11839CRITICAL9.9Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now