2026 CVE Vulnerabilities

45,447 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-59873HIGH7.5node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds...
CVE-2026-59871HIGH7.5node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and lin...
CVE-2026-59870HIGH7.5js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.1, YAML11_SCHEMA support for the !!omap tag in src...
CVE-2026-59869HIGH7.5js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend ...
CVE-2026-59868HIGH7.5js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.0, when merge keys are enabled, js-yaml can spend ...
CVE-2026-59725HIGH7.5Socket.IO enables bidirectional and low-latency communication for every platform. From 4.1.0 before 6.6.7, Engine.IO pro...
CVE-2026-59724HIGH7.5Socket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO ser...
CVE-2026-59262HIGH7.1AFFiNE's histories GraphQL field fails to validate Doc.Read permission before exposing document edit history, allowing a...
CVE-2026-53951HIGH8.8Copier is a library and CLI app for rendering project templates. In versions 9.5.0 through 9.15.1, the `trust` setting's...
CVE-2026-59703HIGH8.7repomix contains a local file inclusion vulnerability in the git clone endpoint that allows unauthenticated attackers to...
CVE-2026-55874HIGH7.7SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in th...
CVE-2026-54652HIGH8.1Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any aut...
CVE-2026-49147HIGH7.5App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output m...
CVE-2026-49146HIGH7.5App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrc. ac...
CVE-2026-49145HIGH7.5App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc. ack searches up th...
CVE-2026-24700HIGH7.2An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with ...
CVE-2026-24699HIGH7.2An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with f...
CVE-2026-24698HIGH7.2An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco RV130/...
CVE-2026-24697HIGH7.2An OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV130W wi...
CVE-2026-15067HIGH8.8Snowflake Terraform Provider versions prior to 2.18.0 contain several security vulnerabilities, including SQL injection ...
CVE-2026-10708HIGH7.5This vulnerability enables large‑scale data harvesting without requiring app‑specific secrets. A single request to a min...
CVE-2026-10706HIGH7.5In Adalo’s no-code app builder, (Versions 1 and 2) the attackers may extract full user records and correlate user behavi...
CVE-2026-10699HIGH7.5Missing release of memory after effective lifetime vulnerability in Progress MOVEit Transfer (Custom Reports modules). ...
CVE-2026-10698HIGH7.2Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Report...
CVE-2026-59257HIGH8.8n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the legacy My...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now