2026 CVE Vulnerabilities
48,297 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10852 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | IBM WebSphere Application Server and IBM WebSphere Application Server Liberty are vulnerable to denial of service in the... |
| CVE-2026-54299 | HIGH | 7.5 | 0.2% | Jun 22, 2026 | Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using export const p... |
| CVE-2026-54293 | HIGH | 7.5 | 0.4% | Jun 22, 2026 | NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research a... |
| CVE-2026-53779 | HIGH | 8.7 | 0.4% | Jun 22, 2026 | WebP Server Go through 0.14.4 contains a path traversal vulnerability on Windows that allows unauthenticated attackers t... |
| CVE-2026-11834 | HIGH | 8.7 | 0.4% | Jun 22, 2026 | A command injection vulnerability has been identified in the DHCP option processing logic in multiple TP-Link router mod... |
| CVE-2026-56109 | HIGH | 7 | 0.1% | Jun 22, 2026 | The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def()... |
| CVE-2026-55602 | HIGH | 8.6 | 0.4% | Jun 22, 2026 | http-proxy-middleware is node.js http-proxy middleware. From 0.16.0 until 2.0.10, 3.0.6, and 4.1.0, http-proxy-middlewar... |
| CVE-2026-55388 | HIGH | 8.1 | 0.3% | Jun 22, 2026 | piscina is a node.js worker pool implementation. Prior to 6.0.0-rc.2, 5.2.0, and 4.9.3, piscina's constructor and run() ... |
| CVE-2026-54290 | HIGH | 7.1 | 0.2% | Jun 22, 2026 | Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.25, with credentials... |
| CVE-2026-54283 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | Starlette is a lightweight ASGI framework/toolkit. From 0.4.1 until 1.3.1, request.form() accepts max_fields and max_par... |
| CVE-2026-54280 | HIGH | 7.5 | 0.2% | Jun 22, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, payload resources are n... |
| CVE-2026-54279 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, host-only cookies that ... |
| CVE-2026-54278 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is po... |
| CVE-2026-54277 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, it is possible to bypas... |
| CVE-2026-54275 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, the server_hostname TLS... |
| CVE-2026-54274 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, if an attacker sends la... |
| CVE-2026-54273 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, no limit was present on... |
| CVE-2026-54271 | HIGH | 8.2 | 0.2% | Jun 22, 2026 | protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.3.2 and 2.5.0, a previous fix for unsafe name hand... |
| CVE-2026-53571 | HIGH | 7.5 | 0.4% | Jun 22, 2026 | Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are s... |
| CVE-2026-53539 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.30, when parsing application/x-www-form-urlenc... |
| CVE-2026-50269 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.0, attacker-controlled inp... |
| CVE-2026-50170 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-50168 | HIGH | 8.2 | 0.2% | Jun 22, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-48712 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.6.1 and 8.4.1, protobufjs could recu... |
| CVE-2026-42127 | HIGH | 7.5 | 0.4% | Jun 22, 2026 | The public dashboard query endpoint does not limit request body size before processing, allowing unauthenticated attacke... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now