2026 CVE Vulnerabilities
45,444 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59803 | HIGH | 8.7 | 0.4% | Jul 8, 2026 | rpcx through 1.9.3, fixed in commit 047aec1, contains a denial-of-service vulnerability in protocol.Message.Decode (prot... |
| CVE-2026-59802 | HIGH | 8.2 | 0.2% | Jul 8, 2026 | PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_ur... |
| CVE-2026-58253 | HIGH | 8.8 | 0.4% | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12.... |
| CVE-2026-58250 | HIGH | 7.5 | 0.7% | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.12.8 and 2.... |
| CVE-2026-58213 | HIGH | 7.1 | 0.4% | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.1 and 2.... |
| CVE-2026-58210 | HIGH | 7.5 | 0.7% | Jul 8, 2026 | NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.... |
| CVE-2026-55760 | HIGH | 7.5 | 0.4% | Jul 8, 2026 | Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.2, applications that pass us... |
| CVE-2026-55575 | HIGH | 8.2 | 0.4% | Jul 8, 2026 | LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.1, the pop array filt... |
| CVE-2026-55404 | HIGH | 8.8 | 0.6% | Jul 8, 2026 | yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the --write-link, --write-url-link, a... |
| CVE-2026-14891 | HIGH | 8.7 | 0.3% | Jul 8, 2026 | HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job s... |
| CVE-2026-14373 | HIGH | 7.7 | 0.2% | Jul 8, 2026 | HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host ... |
| CVE-2026-59937 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with repeated malf... |
| CVE-2026-60102 | HIGH | 8.8 | 1.8% | Jul 8, 2026 | Horde Virtual File System (VFS) API before 3.0.1 contains an OS command injection vulnerability in the Horde_Vfs_Smb dri... |
| CVE-2026-59928 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repe... |
| CVE-2026-59925 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-ast... |
| CVE-2026-59922 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or c... |
| CVE-2026-59892 | HIGH | 7.5 | 0.4% | Jul 8, 2026 | OpenTelemetry JavaScript is the OpenTelemetry JavaScript client. Prior to 2.9.0, @opentelemetry/propagator-jaeger decode... |
| CVE-2026-59887 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | linkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used b... |
| CVE-2026-59879 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#... |
| CVE-2026-59731 | HIGH | 8.2 | 0.3% | Jul 8, 2026 | Astro is a web framework for content-driven websites. Version 6.4.7 performs authorization decisions on a partially deco... |
| CVE-2026-39822 | HIGH | 7.8 | 0.2% | Jul 8, 2026 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina... |
| CVE-2026-29008 | HIGH | 8.7 | 0.4% | Jul 8, 2026 | U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c... |
| CVE-2026-59880 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, Immutable.Map and Immutable.S... |
| CVE-2026-59877 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed opt... |
| CVE-2026-59874 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar he... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now