2026 CVE Vulnerabilities

45,440 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-55596HIGH8.7Plate is a rich-text editor with AI and shadcn/ui. From 53.0.0 until 53.1.4, the media embed renderer trusts serialized ...
CVE-2026-55206HIGH8.7py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryptio...
CVE-2026-55195HIGH8.7py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryptio...
CVE-2026-54591HIGH8.1AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on to...
CVE-2026-54528HIGH7.1JupyterLab Git is a Git extension for JupyterLab. Prior to 0.54.0, jupyterlab-git uses fnmatch.fnmatchcase() in GitHandl...
CVE-2026-49866HIGH7.5libp2p is a JavaScript Implementation of libp2p networking stack. Prior to 16.0.0, @libp2p/gossipsub defaultDecodeRpcLim...
CVE-2026-35210HIGH7.1OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 7.260326.0...
CVE-2026-15169HIGH7.5UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
CVE-2026-15163HIGH7.5Multiple protocol dissector infinite loops in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allow denial of service
CVE-2026-0288HIGH7.5Multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent (TSA) component of Palo Alto Networks PAN-...
CVE-2026-8800HIGH8.8Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transf...
CVE-2026-8651HIGH7.5Limited authentication bypass by spoofing vulnerability in Progress MOVEit Transfer (HTTPS module). This issue affects ...
CVE-2026-8650HIGH7.5Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Tr...
CVE-2026-60104HIGH8Bitwarden Server before 2026.6.0 does not verify that the email in a POST /auth-requests/admin-request body belongs to t...
CVE-2026-59948HIGH7Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an...
CVE-2026-59939HIGH7.5httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression o...
CVE-2026-59936HIGH7.5pypdf is a free and open-source pure-python PDF library. Prior to 6.14.1, an attacker can craft a PDF with a page conten...
CVE-2026-59935HIGH7.5pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page conten...
CVE-2026-59822HIGH8.2LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Str...
CVE-2026-59821HIGH7.2LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's ...
CVE-2026-59807HIGH8.9Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and ex...
CVE-2026-59806HIGH7.4Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to re...
CVE-2026-59805HIGH7.1Gumroad before 2026.07.06.2 contains a broken access control vulnerability in the PurchasesController that allows authen...
CVE-2026-59804HIGH7.6Midscene Bridge Server through 1.10.3, fixed in commit 86f4118, contains a missing authentication and CORS misconfigurat...
CVE-2026-59803HIGH8.7rpcx through 1.9.3, fixed in commit 047aec1, contains a denial-of-service vulnerability in protocol.Message.Decode (prot...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now