2026 CVE Vulnerabilities
45,091 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-6091 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | Partial-chain certificate verification may accept chains that terminate at a peer-supplied, untrusted intermediate certi... |
| CVE-2026-55699 | MEDIUM | 6.5 | 0.3% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.2 and 11.5.3, Manifest bin object keys such as "", ".", and ".." passed pnpm's... |
| CVE-2026-55180 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repositor... |
| CVE-2026-54679 | MEDIUM | 5.5 | 0.1% | Jun 25, 2026 | jq is a command-line JSON processor. Prior to 1.8.2, on 32bit system, jvp_string_append has a chance of integer/multiple... |
| CVE-2026-50017 | MEDIUM | 6.5 | 0.3% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm can send user-level unscoped npm authentication credentials... |
| CVE-2026-47770 | MEDIUM | 5.5 | 0.1% | Jun 25, 2026 | jq is a command-line JSON processor. Prior to 1.8.2, comparing two sufficiently deeply nested arrays with the == operato... |
| CVE-2026-9799 | MEDIUM | 4.6 | 0.2% | Jun 25, 2026 | A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permissio... |
| CVE-2026-9705 | MEDIUM | 6.5 | 0.3% | Jun 25, 2026 | A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registrati... |
| CVE-2026-9083 | MEDIUM | 4.9 | 0.5% | Jun 25, 2026 | A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submi... |
| CVE-2026-55439 | MEDIUM | 5.5 | 0.3% | Jun 25, 2026 | Halo is an open source website building tool. Prior to 2.24.3, a path traversal vulnerability in the backup download end... |
| CVE-2026-55411 | MEDIUM | 6.8 | 0.1% | Jun 25, 2026 | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI ... |
| CVE-2026-54573 | MEDIUM | 5.3 | 0.3% | Jun 25, 2026 | Outline is a service that allows for collaborative documentation. Prior to 1.8.0, the AuthenticationHelper.canAccess fun... |
| CVE-2026-54448 | MEDIUM | 6.5 | 0.3% | Jun 25, 2026 | Trivy is a security scanner. Prior to 0.71.0, when Trivy scans a Helm chart archive (.tgz), its custom tar unpacker read... |
| CVE-2026-54037 | MEDIUM | 6.5 | 0.3% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2025-710... |
| CVE-2026-54033 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, LibreChat allows users t... |
| CVE-2026-54029 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the DELETE /api/messages... |
| CVE-2026-54027 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/files/imag... |
| CVE-2026-54025 | MEDIUM | 5.4 | 0.1% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, there is a vulnerability... |
| CVE-2026-54024 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the fix for CVE-2024-111... |
| CVE-2026-9718 | MEDIUM | 6.5 | 0.2% | Jun 25, 2026 | CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-servi... |
| CVE-2026-9651 | MEDIUM | 4.4 | 0.1% | Jun 25, 2026 | CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of ... |
| CVE-2026-57454 | MEDIUM | 6.1 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. From 9.2.0320 until 9.2.0679, a crafted undo or swap file can store a v... |
| CVE-2026-57452 | MEDIUM | 5.5 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0671, when Vim opens a file encrypted with the VimCrypt~04... |
| CVE-2026-57451 | MEDIUM | 6.1 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0670, get_text_props() in src/textprop.c reads a uint16 pr... |
| CVE-2026-57438 | MEDIUM | 6.6 | 0.1% | Jun 25, 2026 | Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, XInclude substitutio... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now