2026 CVE Vulnerabilities

45,151 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-44273MEDIUM4.4Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials vulnerability. A high...
CVE-2026-55443MEDIUM5.5LangChain is a framework for building agents and LLM-powered applications. Prior to 1.3.9, several LangChain components ...
CVE-2026-54300MEDIUM5.3@astrojs/netlify is an adapter that allows Astro to deploy your hybrid or server rendered site to Netlify. Prior to 7.0....
CVE-2026-54298MEDIUM6.1Astro is a web framework. Prior to 6.4.6, the spreadAttributes function in Astro's server-side rendering pipeline iterat...
CVE-2026-54288MEDIUM6.5Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, the Body Limit M...
CVE-2026-50146MEDIUM6.1Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot content i...
CVE-2026-54289MEDIUM4.8Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda@Ed...
CVE-2026-54287MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on AWS Lambda, t...
CVE-2026-54286MEDIUM5.9Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, on Windows hosts...
CVE-2026-54285MEDIUM5.3opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 2.8.0, W3CBaggagePropagator.extract() in @opentelemetr...
CVE-2026-54282MEDIUM5.3Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being u...
CVE-2026-54276MEDIUM6.1AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, DigestAuthMiddleware ca...
CVE-2026-54270MEDIUM5.3protobufjs compiles protobuf definitions into JavaScript (JS) functions. From 8.2.0 to 8.4.2, protobufjs preserved unkno...
CVE-2026-54269MEDIUM5.3protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 8.6.0 and 7.6.3, protobufjs accepted c...
CVE-2026-53632MEDIUM5.5launch-editor allows users to open files with line numbers in editor from Node.js. Prior to 2.14.1, the launch-editor NP...
CVE-2026-53537MEDIUM5.3Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, parse_options_header parsed Content-Dispos...
CVE-2026-50556MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-50555MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-50184MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-50171MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-50169MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-46417MEDIUM6.1Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-11994MEDIUM4.8Akaunting 3.1.21 contains an authenticated stored Cross-Site Scripting vulnerability in the report management workflow. ...
CVE-2026-9610MEDIUM5.3IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality...
CVE-2026-8934MEDIUM6.9A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud C...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now