2026 CVE Vulnerabilities

64,763 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-45109HIGH7.5Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.18 and 16.2.6, it was ...
CVE-2026-44582LOW3.7Next.js is a React framework for building full-stack web applications. From 13.4.6 to before 15.5.16 and 16.2.5, React S...
CVE-2026-44581MEDIUM4.7Next.js is a React framework for building full-stack web applications. From 13.4.0 to before 15.5.16 and 16.2.5, App Rou...
CVE-2026-44580MEDIUM6.1Next.js is a React framework for building full-stack web applications. From 13.0.0 to before 15.5.16 and 16.2.5, applica...
CVE-2026-44579HIGH7.5Next.js is a React framework for building full-stack web applications. From to before 15.5.16 and 16.2.5, applications ...
CVE-2026-44578HIGH8.6Next.js is a React framework for building full-stack web applications. From 13.4.13 to before 15.5.16 and 16.2.5, self-h...
CVE-2026-44009CRITICAL9.8vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, This vulnerability is fixed in 3.11.2.
CVE-2026-44008CRITICAL9.8vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.2, the new method neutralizeArraySpeciesBatch works with obj...
CVE-2026-44007CRITICAL9.1vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.1, when a NodeVM is created with nesting: true, sandbox code...
CVE-2026-44006CRITICAL10vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, It is possible to reach BaseHandler.getPrototypeOf, which...
CVE-2026-44005CRITICAL10vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-r...
CVE-2026-44004HIGH7.5vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, sandboxed code can call Buffer.alloc() with an arbitrary ...
CVE-2026-44003MEDIUM5.8vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's code transformer has a performance optimization tha...
CVE-2026-44002MEDIUM5.8vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, vm2's CallSite wrapper class (intended as a safe wrapper ...
CVE-2026-44001HIGH8.6vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox escape vulnerability in vm2 v3.10.5 allows any ...
CVE-2026-44000HIGH7.2vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox boundary violation in vm2 allows host object id...
CVE-2026-43999CRITICAL9.9vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, NodeVM's builtin allowlist can be bypassed when the modul...
CVE-2026-43998HIGH8.5vm2 is an open source vm/sandbox for Node.js. In 3.10.5, NodeVM's require.root path restriction can be bypassed using fi...
CVE-2026-43997CRITICAL10vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, it is possible to obtain the host Object. There are vario...
CVE-2026-0265HIGH8.1An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with n...
CVE-2026-0264CRITICAL9.8A buffer overflow vulnerability in the DNS proxy and DNS Server features of Palo Alto Networks PAN-OS® Software allows a...
CVE-2026-0263CRITICAL9.8A buffer overflow vulnerability in the IKEv2 processing of Palo Alto Networks PAN-OS® software allows an unauthenticated...
CVE-2026-0237HIGH7.8An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly ...
CVE-2026-44577MEDIUM5.9Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when se...
CVE-2026-44576MEDIUM5.4Next.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applica...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now