2026 CVE Vulnerabilities
46,928 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59892 | HIGH | 7.5 | 0.4% | Jul 8, 2026 | OpenTelemetry JavaScript is the OpenTelemetry JavaScript client. Prior to 2.9.0, @opentelemetry/propagator-jaeger decode... |
| CVE-2026-59887 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | linkify-it is a links recognition library with full Unicode support. Prior to 5.0.2, the mailto: schema validator used b... |
| CVE-2026-59879 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#... |
| CVE-2026-59731 | HIGH | 8.2 | 0.3% | Jul 8, 2026 | Astro is a web framework for content-driven websites. Version 6.4.7 performs authorization decisions on a partially deco... |
| CVE-2026-39822 | HIGH | 7.8 | 0.2% | Jul 8, 2026 | On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the fina... |
| CVE-2026-29008 | HIGH | 8.7 | 0.4% | Jul 8, 2026 | U-Boot through 2026.04-rc3 contains an integer underflow vulnerability in the tcp_rx_state_machine() function (net/tcp.c... |
| CVE-2026-59880 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, Immutable.Map and Immutable.S... |
| CVE-2026-59877 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.5 and 8.6.6, protobufjs parsed opt... |
| CVE-2026-59874 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar he... |
| CVE-2026-59873 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds... |
| CVE-2026-59871 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and lin... |
| CVE-2026-59870 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.1, YAML11_SCHEMA support for the !!omap tag in src... |
| CVE-2026-59869 | HIGH | 7.5 | 0.4% | Jul 8, 2026 | js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend ... |
| CVE-2026-59868 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 before 5.2.0, when merge keys are enabled, js-yaml can spend ... |
| CVE-2026-59725 | HIGH | 7.5 | 0.4% | Jul 8, 2026 | Socket.IO enables bidirectional and low-latency communication for every platform. From 4.1.0 before 6.6.7, Engine.IO pro... |
| CVE-2026-59724 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | Socket.IO enables bidirectional and low-latency communication for every platform. From 6.5.0 before 6.6.7, Engine.IO ser... |
| CVE-2026-59262 | HIGH | 7.1 | 0.2% | Jul 8, 2026 | AFFiNE's histories GraphQL field fails to validate Doc.Read permission before exposing document edit history, allowing a... |
| CVE-2026-53951 | HIGH | 8.8 | 0.2% | Jul 8, 2026 | Copier is a library and CLI app for rendering project templates. In versions 9.5.0 through 9.15.1, the `trust` setting's... |
| CVE-2026-59703 | HIGH | 8.7 | 0.4% | Jul 8, 2026 | repomix contains a local file inclusion vulnerability in the git clone endpoint that allows unauthenticated attackers to... |
| CVE-2026-55874 | HIGH | 7.7 | — | Jul 8, 2026 | SeaweedFS is a distributed storage system. Prior to 4.34, the S3 API gateway does not reject dot-dot path segments in th... |
| CVE-2026-54652 | HIGH | 8.1 | — | Jul 8, 2026 | Frigate is an open source network video recorder. In version 0.17.1, the GET /api/logs/{service} endpoint allows any aut... |
| CVE-2026-49147 | HIGH | 7.5 | — | Jul 8, 2026 | App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output m... |
| CVE-2026-49146 | HIGH | 7.5 | — | Jul 8, 2026 | App::Ack versions before 3.10.0 for Perl allow memory exhaustion via an unbounded context value in a project .ackrc. ac... |
| CVE-2026-49145 | HIGH | 7.5 | — | Jul 8, 2026 | App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc. ack searches up th... |
| CVE-2026-24700 | HIGH | 7.2 | 1.0% | Jul 8, 2026 | An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now