2026 CVE Vulnerabilities

48,297 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-10852HIGH7.5IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the...
CVE-2026-54299HIGH7.5Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using export const p...
CVE-2026-54293HIGH7.5NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a...
CVE-2026-53779HIGH8.7WebP Server Go through 0.14.4 contains a path traversal vulnerability on Windows that allows unauthenticated attackers t...
CVE-2026-11834HIGH8.7A command injection vulnerability has been identified in the DHCP option processing logic in multiple TP-Link router mod...
CVE-2026-56109HIGH7The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def()...
CVE-2026-55602HIGH8.6http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middlewar...
CVE-2026-55388HIGH8.1piscina is a node.js worker pool implementation. Prior to 6.0.0-rc.2, 5.2.0, and 4.9.3, piscina's constructor and run() ...
CVE-2026-54290HIGH7.1Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, with credentials...
CVE-2026-54283HIGH7.5Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_par...
CVE-2026-54280HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are n...
CVE-2026-54279HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that ...
CVE-2026-54278HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is po...
CVE-2026-54277HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypas...
CVE-2026-54275HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS...
CVE-2026-54274HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends la...
CVE-2026-54273HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on...
CVE-2026-54271HIGH8.2protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.3.2 and 2.5.0, a previous fix for unsafe name hand...
CVE-2026-53571HIGH7.5Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are s...
CVE-2026-53539HIGH7.5Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlenc...
CVE-2026-50269HIGH7.5AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled inp...
CVE-2026-50170HIGH7.5Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-50168HIGH8.2Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other...
CVE-2026-48712HIGH7.5protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.1 and 8.4.1, protobufjs could recu...
CVE-2026-42127HIGH7.5The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attacke...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now