2026 CVE Vulnerabilities

64,935 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41327CRITICAL9.1Dgraph is an open source distributed GraphQL database. Prior to 25.3.3, a vulnerability has been found in Dgraph that gi...
CVE-2026-41326HIGH8.2Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) th...
CVE-2026-33666HIGH7.5Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18....
CVE-2026-33662HIGH7.5OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Corte...
CVE-2026-33524HIGH7.5Zserio is a framework for serializing structured data with a compact and efficient way with low overhead. Prior to 2.18....
CVE-2026-42044CRITICAL9.1Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.2, he Axios library is vulne...
CVE-2026-42043CRITICAL10Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, an attacker who can influe...
CVE-2026-42042MEDIUM5.4Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library's XSRF t...
CVE-2026-42041MEDIUM6.5Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the Axios library is vulne...
CVE-2026-42040LOW3.7Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, the encode() function in l...
CVE-2026-42039HIGH7.5Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, toFormData recursively wal...
CVE-2026-42038HIGH7.5Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, he fix for no_proxy hostna...
CVE-2026-42037MEDIUM5.3Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.15.1, the FormDataPart construc...
CVE-2026-42036MEDIUM5.3Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when responseType: 'stream...
CVE-2026-42035HIGH7.4Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, a prototype pollution gadg...
CVE-2026-42034MEDIUM5.3Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, for stream request bodies,...
CVE-2026-42033HIGH7.4Axios is a promise based HTTP client for the browser and Node.js. Prior to 1.15.1 and 0.31.1, when Object.prototype has ...
CVE-2026-41898MEDIUM5.3rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.24 to before 0.10.78, the FFI trampo...
CVE-2026-41681HIGH7.5rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.39 to before 0.10.78, EVP_DigestFin...
CVE-2026-41680HIGH7.5Marked is a markdown parser and compiler. From 18.0.0 to 18.0.1, a critical Denial of Service (DoS) vulnerability exists...
CVE-2026-41678HIGH8.1rust-openssl provides OpenSSL bindings for the Rust programming language. From to before 0.10.78, aes::unwrap_key() co...
CVE-2026-41677CRITICAL9.1rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.0 to before 0.10.78, the *_from_pem_...
CVE-2026-41676HIGH7.5rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.9.27 to before 0.10.78, Deriver::deriv...
CVE-2026-41322MEDIUM5.3@astrojs/node allows Astro to deploy your SSR site to Node targets. Prior to 10.0.5, requesting a static js/css resource...
CVE-2026-41321LOW2.2@astrojs/cloudflare is an SSR adapter for use with Cloudflare Workers targets. Prior to 13.1.10, the fetch() call for re...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now