2026 CVE Vulnerabilities

48,557 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-46654HIGH8.9Plonky3 is a toolkit for polynomial IOPs (PIOPs). Prior to versions 0.4.3 and 0.5.3, an attacker controlling prover-side...
CVE-2026-46625HIGH7.5JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal as...
CVE-2026-46522HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.2...
CVE-2026-46520HIGH7.5ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-...
CVE-2026-45783HIGH7.5libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 16.2.6, an unauthenticated remote pee...
CVE-2026-44692HIGH7.7Sharp is a content management framework built for Laravel as a package. Prior to version 9.22.0, Sharp exposes a generic...
CVE-2026-42542HIGH7.5TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3...
CVE-2026-42462HIGH7Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10...
CVE-2026-2049HIGH7.8GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote a...
CVE-2026-10143HIGH7.5kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handling that allows a ma...
CVE-2026-10142HIGH8.7kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious br...
CVE-2026-0273HIGH7.2A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypas...
CVE-2026-0272HIGH7.2A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with a...
CVE-2026-0271HIGH7.8A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a l...
CVE-2026-0270HIGH7.5A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenti...
CVE-2026-6893HIGH7.5A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specia...
CVE-2026-46643HIGH7.5Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.1...
CVE-2026-46529HIGH8.4Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote co...
CVE-2026-1220HIGH7.5Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a...
CVE-2026-50637HIGH8.2Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections. The statsd prot...
CVE-2026-9151HIGH8.5An OS command injection vulnerability exists in the VPN module of TP-Link Archer AX12 v1, AX17 v1. AX18 v1, and AX1300 v...
CVE-2026-50570HIGH8.5Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic...
CVE-2026-50567HIGH7.7Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic...
CVE-2026-49824HIGH8.5Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic...
CVE-2026-49823HIGH7.7Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now