2026 CVE Vulnerabilities

45,141 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-54911MEDIUM6.5UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.13.0, ujson.dum...
CVE-2026-48500MEDIUM6.5Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5, ...
CVE-2026-48167MEDIUM6.4Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5...
CVE-2026-48166MEDIUM5.3Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5...
CVE-2026-48067MEDIUM6.5Filament is a collection of full-stack components for accelerated Laravel development. From filament/actions 4.0.0 until...
CVE-2026-44889MEDIUM6.1WebOb provides objects for HTTP requests and responses. Prior to 1.8.10, the normalization of the HTTP Location header d...
CVE-2026-44311MEDIUM6.1Fabric.js is a Javascript HTML5 canvas library. Prior to 7.4.0, a potential Cross-Site Scripting (XSS) vulnerability exi...
CVE-2026-55599MEDIUM5.8phpseclib is a PHP secure communications library. From 0.1.1 until 1.0.30, 2.0.55, and 3.0.54, when an application valid...
CVE-2026-54651MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.13.1, an attacker who uses this vulnerability can cr...
CVE-2026-54531MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can cr...
CVE-2026-54530MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.13.0, an attacker who uses this vulnerability can cr...
CVE-2026-49461MEDIUM5.5pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can cr...
CVE-2026-47242MEDIUM5.8Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, wh...
CVE-2026-47240MEDIUM5.8Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, se...
CVE-2026-44727MEDIUM5.4Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server...
CVE-2026-41479MEDIUM5.4Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2....
CVE-2026-44273MEDIUM4.4Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials vulnerability. A high...
CVE-2026-55443MEDIUM5.5LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components ...
CVE-2026-54300MEDIUM5.3@astrojs/netlify is an adapter that allows Astro to deploy your hybrid or server rendered site to Netlify. Prior to 7.0....
CVE-2026-54298MEDIUM6.1Astro is a web framework. Prior to 6.4.6, the spreadAttributes function in Astro's server-side rendering pipeline iterat...
CVE-2026-54288MEDIUM6.5Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, the Body Limit M...
CVE-2026-50146MEDIUM6.1Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot content i...
CVE-2026-54289MEDIUM4.8Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda@Ed...
CVE-2026-54287MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda, t...
CVE-2026-54286MEDIUM5.9Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now