2026 CVE Vulnerabilities

48,096 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-55700HIGH7.1pnpm is a package manager. From 11.3.0 until 11.5.3, `pnpm stage download` derived a local filename from registry-contro...
CVE-2026-55698HIGH8.8pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first...
CVE-2026-55697HIGH8.8pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can install configDependencies declared in pnpm-workspace.y...
CVE-2026-55487HIGH8.8pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized t...
CVE-2026-50573HIGH8.1pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` in non-frozen mode can accept new remote package ...
CVE-2026-50021HIGH8.1pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's tarball extraction worker skips integrity verification wh...
CVE-2026-50016HIGH8.8pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package ...
CVE-2026-50015HIGH7.3pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's patch application pipeline (@pnpm/patch-package) performs...
CVE-2026-50014HIGH7.3pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm passes the lockfile-controlled git resolution.commit value ...
CVE-2026-49839HIGH7.1jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into inval...
CVE-2026-48995HIGH7.5pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarbal...
CVE-2026-11999HIGH7.5X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_...
CVE-2026-9800HIGH8.1A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorizati...
CVE-2026-9099HIGH7.7A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin RE...
CVE-2026-9086HIGH7.3A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` ...
CVE-2026-55412HIGH8.3ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI ...
CVE-2026-55092HIGH7.5Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image...
CVE-2026-54040HIGH7.1LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/auth/2fa/b...
CVE-2026-45233HIGH8.1HTMLy CMS through 3.1.1 contains a path traversal vulnerability that allows low-privileged authenticated attackers to re...
CVE-2026-13351HIGH7.5Zephyr's IPv6 network stack can be prevented from receiving or processing future incoming packets by sending a small num...
CVE-2026-9717HIGH7.2CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could...
CVE-2026-9716HIGH7.5CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the devi...
CVE-2026-9650HIGH7.5CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitiv...
CVE-2026-57456HIGH7.8Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/pytho...
CVE-2026-57455HIGH7.8Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now