2026 CVE Vulnerabilities

46,924 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-59936HIGH7.5pypdf is a free and open-source pure-python PDF library. Prior to 6.14.1, an attacker can craft a PDF with a page conten...
CVE-2026-59935HIGH7.5pypdf is a free and open-source pure-python PDF library. Prior to 6.14.2, an attacker can craft a PDF with a page conten...
CVE-2026-59822HIGH8.2LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Str...
CVE-2026-59821HIGH7.2LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.82.0-stable, LiteLLM's ...
CVE-2026-59807HIGH8.9Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and ex...
CVE-2026-59806HIGH7.4Gradio before 6.20.0 contains an open redirect and server-side request forgery vulnerability that allows attackers to re...
CVE-2026-59805HIGH7.1Gumroad before 2026.07.06.2 contains a broken access control vulnerability in the PurchasesController that allows authen...
CVE-2026-59804HIGH7.6Midscene Bridge Server through 1.10.3, fixed in commit 86f4118, contains a missing authentication and CORS misconfigurat...
CVE-2026-59803HIGH8.7rpcx through 1.9.3, fixed in commit 047aec1, contains a denial-of-service vulnerability in protocol.Message.Decode (prot...
CVE-2026-59802HIGH8.2PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_ur...
CVE-2026-58253HIGH8.8NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.0, 2.12....
CVE-2026-58250HIGH7.5NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.12.8 and 2....
CVE-2026-58213HIGH7.1NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.1 and 2....
CVE-2026-58210HIGH7.5NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2....
CVE-2026-55760HIGH7.5Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.2, applications that pass us...
CVE-2026-55575HIGH8.2LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.1, the pop array filt...
CVE-2026-55404HIGH8.8yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the --write-link, --write-url-link, a...
CVE-2026-14891HIGH8.7HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job s...
CVE-2026-14373HIGH7.7HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host ...
CVE-2026-59937HIGH7.5pypdf is a free and open-source pure-python PDF library. Prior to 6.14.0, an attacker can craft a PDF with repeated malf...
CVE-2026-60102HIGH8.8Horde Virtual File System (VFS) API before 3.0.1 contains an OS command injection vulnerability in the Horde_Vfs_Smb dri...
CVE-2026-59928HIGH7.5Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repe...
CVE-2026-59925HIGH7.5Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-ast...
CVE-2026-59922HIGH7.5Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or c...
CVE-2026-59892HIGH7.5OpenTelemetry JavaScript is the OpenTelemetry JavaScript client. Prior to 2.9.0, @opentelemetry/propagator-jaeger decode...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now