2026 CVE Vulnerabilities

48,557 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-44494HIGH8.7Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vuln...
CVE-2026-44492HIGH8.6Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios does not normalise I...
CVE-2026-44490HIGH8.2Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-sid...
CVE-2026-44488HIGH7.5Axios is a promise based HTTP client for the browser and Node.js. Axios versions 1.7.0 through 1.15.x did not enforce co...
CVE-2026-44487HIGH7.5Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapt...
CVE-2026-44486HIGH7.5Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapte...
CVE-2026-11945HIGH7.5PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON docume...
CVE-2026-7870HIGH8.8IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malici...
CVE-2026-7787HIGH8.1IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypass...
CVE-2026-53777HIGH8.6Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary co...
CVE-2026-8406HIGH7.1openSIS Classic 9.3 contains an insecure direct object reference vulnerability in the messaging module. Any authenticate...
CVE-2026-53661HIGH8.8Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized iden...
CVE-2026-11816HIGH8.1Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `...
CVE-2026-10847HIGH7.8A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated lo...
CVE-2026-8589HIGH8.7GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and...
CVE-2026-8464HIGH8.3Golem OEE MES is vulnerable to an unauthenticated path traversal flaw. This vulnerability allows an attacker in the same...
CVE-2026-7250HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, a...
CVE-2026-10087HIGH8.7GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5, and 1...
CVE-2026-5497HIGH7.5vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded f...
CVE-2026-53901HIGH8.7Cerebrate before version 1.37 contains a mass-assignment vulnerability in the generic CRUD add path. The add() handler a...
CVE-2026-41856HIGH7.5The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on...
CVE-2026-41700HIGH8.1Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacki...
CVE-2026-40999HIGH8.6When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections ...
CVE-2026-40998HIGH8.2Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed atta...
CVE-2026-40994HIGH8.2Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation di...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now