2026 CVE Vulnerabilities

48,535 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-44479MEDIUM5.5Vercel’s AI Cloud is a unified platform for building modern applications. From 50.16.0 to 52.0.0, hen the Vercel CLI ru...
CVE-2026-44467MEDIUM6.8The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side...
CVE-2026-44458MEDIUM4.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, the JSX renderer...
CVE-2026-44457MEDIUM5.3Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.18, Cache Middleware...
CVE-2026-44456MEDIUM6.5Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, bodyLimit() does...
CVE-2026-44455MEDIUM6.1Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.16, Improper handlin...
CVE-2026-44431MEDIUM5.3urllib3 is an HTTP client library for Python. From 1.23 to before 2.7.0, cross-origin redirects followed from the low-le...
CVE-2026-44294MEDIUM5.3protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated ...
CVE-2026-44292MEDIUM5.3protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated ...
CVE-2026-44288MEDIUM5.3protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a...
CVE-2026-43489MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: liveupdate: luo_file: remember retrieve() status L...
CVE-2026-43488MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: usb: xhci: Prevent interrupt storm on host controll...
CVE-2026-43487MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ata: libata-core: Disable LPM on ST1000DM010-2EP102...
CVE-2026-43486MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: arm64: contpte: fix set_access_flags() no-op check ...
CVE-2026-43485MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: nouveau/gsp: drop WARN_ON in ACPI probes These WAR...
CVE-2026-43484MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: mmc: core: Avoid bitfield RMW for claim/retune flag...
CVE-2026-43483MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Set/clear CR8 write interception when AVI...
CVE-2026-43482MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: sched_ext: Disable preemption between scx_claim_exi...
CVE-2026-43480MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ASoC: amd: acp3x-rt5682-max9836: Add missing error ...
CVE-2026-43479MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: net: usb: lan78xx: fix WARN in __netif_napi_del_loc...
CVE-2026-43478MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: ASoC: codecs: rt1011: Use component to get the dapm...
CVE-2026-43477MEDIUM5.5In the Linux kernel, the following vulnerability has been resolved: drm/i915/vrr: Configure VRR timings after enabling ...
CVE-2026-42934MEDIUM6.3NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When charset, source_charse...
CVE-2026-42926MEDIUM6.3When NGINX Open Source is configured to proxy HTTP/2 traffic by setting proxy_http_version to 2, and also uses proxy_set...
CVE-2026-42780MEDIUM6.9A directory traversal vulnerability exists in BIG-IP SSL Orchestrator that allows an authenticated attacker with high pr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now