2026 CVE Vulnerabilities

44,088 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-59927MEDIUM5.3Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/dir...
CVE-2026-59926MEDIUM6.1Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/direc...
CVE-2026-59924MEDIUM5.9Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes use...
CVE-2026-59923MEDIUM6.1Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block p...
CVE-2026-59897MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. From 4.3.3 before 4.12.27, the AWS...
CVE-2026-59896MEDIUM6.5Hono is a Web application framework that provides support for any JavaScript runtime. From 4.11.8 before 4.12.27, hono/j...
CVE-2026-59895MEDIUM6.1Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in...
CVE-2026-59890MEDIUM6.1setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to ...
CVE-2026-59883MEDIUM6.1Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bar...
CVE-2026-59882MEDIUM6.5guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not ...
CVE-2026-59261MEDIUM6.5OpenClaw before 2026.5.28 contains a credential exposure vulnerability where workspace dotenv files can override provide...
CVE-2026-42505MEDIUM5.3Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of...
CVE-2026-29007MEDIUM6.9U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerability in tcp_rx_state_machine() (net/tcp.c) when CONFI...
CVE-2026-59876MEDIUM4.8protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 until 8.6.5, the protobufjs Text For...
CVE-2026-59875MEDIUM5.3node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX ...
CVE-2026-57439MEDIUM5CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.2.0, the Series Chart opera...
CVE-2026-55761MEDIUM5.9Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used t...
CVE-2026-54344MEDIUM4.7ToolJet is an open-source low-code platform for building internal tools. Prior to 3.20.180, ToolJet's render preview dep...
CVE-2026-15063MEDIUM6.3A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication...
CVE-2026-55873MEDIUM4.3SeaweedFS is a distributed storage system. In versions 4.08 through 4.33, requests signed with SigV4 service s3tables ar...
CVE-2026-55668MEDIUM6.3File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor ...
CVE-2026-15044MEDIUM6.3A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific s...
CVE-2026-15036MEDIUM4.3A vulnerability was determined in Harness up to 2.28.2. This vulnerability affects the function getAuthorizedSpaces of t...
CVE-2026-11903MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Tr...
CVE-2026-60125MEDIUM5.3MISP’s importModule() path used getEnabledModule() to resolve a single import module by name, but this lookup did not en...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now