2026 CVE Vulnerabilities

45,091 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-6091MEDIUM6.5Partial-chain certificate verification may accept chains that terminate at a peer-supplied, untrusted intermediate certi...
CVE-2026-55699MEDIUM6.5pnpm is a package manager. Prior to 10.34.2 and 11.5.3, Manifest bin object keys such as "", ".", and ".." passed pnpm's...
CVE-2026-55180MEDIUM6.5pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repositor...
CVE-2026-54679MEDIUM5.5jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple...
CVE-2026-50017MEDIUM6.5pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm can send user-level unscoped npm authentication credentials...
CVE-2026-47770MEDIUM5.5jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operato...
CVE-2026-9799MEDIUM4.6A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permissio...
CVE-2026-9705MEDIUM6.5A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registrati...
CVE-2026-9083MEDIUM4.9A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submi...
CVE-2026-55439MEDIUM5.5Halo is an open source website building tool. Prior to 2.24.3, a path traversal vulnerability in the backup download end...
CVE-2026-55411MEDIUM6.8ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI ...
CVE-2026-54573MEDIUM5.3Outline is a service that allows for collaborative documentation. Prior to 1.8.0, the AuthenticationHelper.canAccess fun...
CVE-2026-54448MEDIUM6.5Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker read...
CVE-2026-54037MEDIUM6.5LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2025-710...
CVE-2026-54033MEDIUM6.5LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, LibreChat allows users t...
CVE-2026-54029MEDIUM6.5LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages...
CVE-2026-54027MEDIUM6.5LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/files/imag...
CVE-2026-54025MEDIUM5.4LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, there is a vulnerability...
CVE-2026-54024MEDIUM6.5LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2024-111...
CVE-2026-9718MEDIUM6.5CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-servi...
CVE-2026-9651MEDIUM4.4CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of ...
CVE-2026-57454MEDIUM6.1Vim is an open source, command line text editor. From 9.2.0320 until 9.2.0679, a crafted undo or swap file can store a v...
CVE-2026-57452MEDIUM5.5Vim is an open source, command line text editor. Prior to 9.2.0671, when Vim opens a file encrypted with the VimCrypt~04...
CVE-2026-57451MEDIUM6.1Vim is an open source, command line text editor. Prior to 9.2.0670, get_text_props() in src/textprop.c reads a uint16 pr...
CVE-2026-57438MEDIUM6.6Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, XInclude substitutio...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now