2026 CVE Vulnerabilities
45,151 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44273 | MEDIUM | 4.4 | 0.1% | Jun 22, 2026 | Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials vulnerability. A high... |
| CVE-2026-55443 | MEDIUM | 5.5 | 0.2% | Jun 22, 2026 | LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components ... |
| CVE-2026-54300 | MEDIUM | 5.3 | 0.2% | Jun 22, 2026 | @astrojs/netlify is an adapter that allows Astro to deploy your hybrid or server rendered site to Netlify. Prior to 7.0.... |
| CVE-2026-54298 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Astro is a web framework. Prior to 6.4.6, the spreadAttributes function in Astro's server-side rendering pipeline iterat... |
| CVE-2026-54288 | MEDIUM | 6.5 | 0.1% | Jun 22, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, the Body Limit M... |
| CVE-2026-50146 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot content i... |
| CVE-2026-54289 | MEDIUM | 4.8 | 0.1% | Jun 22, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda@Ed... |
| CVE-2026-54287 | MEDIUM | 5.3 | 0.2% | Jun 22, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda, t... |
| CVE-2026-54286 | MEDIUM | 5.9 | 0.3% | Jun 22, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts... |
| CVE-2026-54285 | MEDIUM | 5.3 | 0.2% | Jun 22, 2026 | opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 2.8.0, W3CBaggagePropagator.extract() in @opentelemetr... |
| CVE-2026-54282 | MEDIUM | 5.3 | 0.2% | Jun 22, 2026 | Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being u... |
| CVE-2026-54276 | MEDIUM | 6.1 | 0.3% | Jun 22, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware ca... |
| CVE-2026-54270 | MEDIUM | 5.3 | 0.3% | Jun 22, 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 to 8.4.2, protobufjs preserved unkno... |
| CVE-2026-54269 | MEDIUM | 5.3 | 0.2% | Jun 22, 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 8.6.0 and 7.6.3, protobufjs accepted c... |
| CVE-2026-53632 | MEDIUM | 5.5 | 0.3% | Jun 22, 2026 | launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NP... |
| CVE-2026-53537 | MEDIUM | 5.3 | 0.2% | Jun 22, 2026 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Dispos... |
| CVE-2026-50556 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-50555 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-50184 | MEDIUM | 6.1 | 0.1% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-50171 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-50169 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-46417 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-11994 | MEDIUM | 4.8 | 0.3% | Jun 22, 2026 | Akaunting 3.1.21 contains an authenticated stored Cross-Site Scripting vulnerability in the report management workflow. ... |
| CVE-2026-9610 | MEDIUM | 5.3 | 0.1% | Jun 22, 2026 | IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality... |
| CVE-2026-8934 | MEDIUM | 6.9 | 0.4% | Jun 22, 2026 | A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud C... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now