2026 CVE Vulnerabilities

64,766 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-0237HIGH7.8An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly ...
CVE-2026-44577MEDIUM5.9Next.js is a React framework for building full-stack web applications. From 10.0.0 to before 15.5.16 and 16.2.5, when se...
CVE-2026-44576MEDIUM5.4Next.js is a React framework for building full-stack web applications. From 14.2.0 to before 15.5.16 and 16.2.5, applica...
CVE-2026-44575HIGH7.5Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Rou...
CVE-2026-44574HIGH8.1Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applica...
CVE-2026-44573HIGH7.5Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applica...
CVE-2026-2695MEDIUM6.3A command injection vulnerability was discovered in TeamViewer DEX Platform On-Premises (former 1E DEX Platform On-Premi...
CVE-2026-8367MEDIUM5.3aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (...
CVE-2026-6282HIGH8.6A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that ...
CVE-2026-6281HIGH8.8A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authentic...
CVE-2026-45740HIGH7.5protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.8 and 8.2.0, protobufjs could recu...
CVE-2026-45033HIGH7.8GitHub Copilot CLI brings AI-powered coding assistance directly to your command line. Prior to 1.0.43, a security vulne...
CVE-2026-45028MEDIUM6.1Astro is a web framework. Astro versions prior to 6.1.10 used AES-GCM encryption to protect the confidentiality and inte...
CVE-2026-44665MEDIUM6.1fast-xml-builder builds XML from JSON. Prior to 1.1.7, when an input data has quotes in attribute values but process ent...
CVE-2026-44664MEDIUM6.1fast-xml-builder builds XML from JSON. In 1.1.5, the fix for CVE-2026-41650 in fast-xml-parser sanitizes -- sequences in...
CVE-2026-44572MEDIUM5.9Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an exte...
CVE-2026-44479MEDIUM5.5Vercel’s AI Cloud is a unified platform for building modern applications. From 50.16.0 to 52.0.0, hen the Vercel CLI ru...
CVE-2026-44470HIGH7.8The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side...
CVE-2026-44467MEDIUM6.8The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side...
CVE-2026-44459LOW3.8Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, improper validat...
CVE-2026-44458MEDIUM4.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, the JSX renderer...
CVE-2026-44457MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, Cache Middleware...
CVE-2026-44456MEDIUM6.5Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, bodyLimit() does...
CVE-2026-44455MEDIUM6.1Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, Improper handlin...
CVE-2026-44432HIGH7.5urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response in...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now