2026 CVE Vulnerabilities
48,096 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-55700 | HIGH | 7.1 | 0.3% | Jun 25, 2026 | pnpm is a package manager. From 11.3.0 until 11.5.3, `pnpm stage download` derived a local filename from registry-contro... |
| CVE-2026-55698 | HIGH | 8.8 | 0.2% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first... |
| CVE-2026-55697 | HIGH | 8.8 | 0.1% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can install configDependencies declared in pnpm-workspace.y... |
| CVE-2026-55487 | HIGH | 8.8 | 0.1% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized t... |
| CVE-2026-50573 | HIGH | 8.1 | 0.1% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` in non-frozen mode can accept new remote package ... |
| CVE-2026-50021 | HIGH | 8.1 | 0.1% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's tarball extraction worker skips integrity verification wh... |
| CVE-2026-50016 | HIGH | 8.8 | 0.3% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package ... |
| CVE-2026-50015 | HIGH | 7.3 | 0.3% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's patch application pipeline (@pnpm/patch-package) performs... |
| CVE-2026-50014 | HIGH | 7.3 | 0.2% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm passes the lockfile-controlled git resolution.commit value ... |
| CVE-2026-49839 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | jq is a command-line JSON processor. Prior to 1.8.2,` jq --rawfile` can turn a handled oversized-string error into inval... |
| CVE-2026-48995 | HIGH | 7.5 | 0.1% | Jun 25, 2026 | pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarbal... |
| CVE-2026-11999 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_... |
| CVE-2026-9800 | HIGH | 8.1 | 0.3% | Jun 25, 2026 | A flaw was found in Keycloak Policy Enforcer. This vulnerability allows any authenticated user to bypass all authorizati... |
| CVE-2026-9099 | HIGH | 7.7 | 0.3% | Jun 25, 2026 | A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin RE... |
| CVE-2026-9086 | HIGH | 7.3 | 0.4% | Jun 25, 2026 | A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` ... |
| CVE-2026-55412 | HIGH | 8.3 | 0.2% | Jun 25, 2026 | ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI ... |
| CVE-2026-55092 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image... |
| CVE-2026-54040 | HIGH | 7.1 | 0.2% | Jun 25, 2026 | LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the POST /api/auth/2fa/b... |
| CVE-2026-45233 | HIGH | 8.1 | 0.6% | Jun 25, 2026 | HTMLy CMS through 3.1.1 contains a path traversal vulnerability that allows low-privileged authenticated attackers to re... |
| CVE-2026-13351 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | Zephyr's IPv6 network stack can be prevented from receiving or processing future incoming packets by sending a small num... |
| CVE-2026-9717 | HIGH | 7.2 | 1.0% | Jun 25, 2026 | CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could... |
| CVE-2026-9716 | HIGH | 7.5 | 0.3% | Jun 25, 2026 | CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the devi... |
| CVE-2026-9650 | HIGH | 7.5 | 0.2% | Jun 25, 2026 | CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitiv... |
| CVE-2026-57456 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/pytho... |
| CVE-2026-57455 | HIGH | 7.8 | 0.1% | Jun 25, 2026 | Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now