2026 CVE Vulnerabilities
50,995 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44001 | HIGH | 8.6 | 0.4% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox escape vulnerability in vm2 v3.10.5 allows any ... |
| CVE-2026-44000 | HIGH | 7.2 | 0.2% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox boundary violation in vm2 allows host object id... |
| CVE-2026-43998 | HIGH | 8.5 | 0.7% | May 13, 2026 | vm2 is an open source vm/sandbox for Node.js. In 3.10.5, NodeVM's require.root path restriction can be bypassed using fi... |
| CVE-2026-0265 | HIGH | 8.1 | 0.4% | May 13, 2026 | An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with n... |
| CVE-2026-0237 | HIGH | 7.8 | 0.1% | May 13, 2026 | An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly ... |
| CVE-2026-44575 | HIGH | 7.5 | 1.6% | May 13, 2026 | Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Rou... |
| CVE-2026-44574 | HIGH | 8.1 | 0.6% | May 13, 2026 | Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applica... |
| CVE-2026-44573 | HIGH | 7.5 | 0.6% | May 13, 2026 | Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applica... |
| CVE-2026-6282 | HIGH | 8.6 | 0.4% | May 13, 2026 | A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that ... |
| CVE-2026-6281 | HIGH | 8.8 | 0.4% | May 13, 2026 | A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authentic... |
| CVE-2026-45740 | HIGH | 7.5 | 0.3% | May 13, 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.8 and 8.2.0, protobufjs could recu... |
| CVE-2026-45033 | HIGH | 7.8 | 0.4% | May 13, 2026 | GitHub Copilot CLI brings AI-powered coding assistance directly to your command line. Prior to 1.0.43, a security vulne... |
| CVE-2026-44470 | HIGH | 7.8 | 0.2% | May 13, 2026 | The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side... |
| CVE-2026-44432 | HIGH | 7.5 | 0.7% | May 13, 2026 | urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response in... |
| CVE-2026-44295 | HIGH | 8.7 | 0.4% | May 13, 2026 | protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbjs static code generation could e... |
| CVE-2026-44293 | HIGH | 8.8 | 0.4% | May 13, 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated ... |
| CVE-2026-44291 | HIGH | 8.1 | 0.5% | May 13, 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs used plain... |
| CVE-2026-44290 | HIGH | 7.5 | 0.4% | May 13, 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs allowed ce... |
| CVE-2026-44289 | HIGH | 7.5 | 0.6% | May 13, 2026 | protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recu... |
| CVE-2026-43481 | HIGH | 7.8 | 0.1% | May 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: net-shapers: don't free reply skb after genlmsg_rep... |
| CVE-2026-43476 | HIGH | 7.8 | 0.1% | May 13, 2026 | In the Linux kernel, the following vulnerability has been resolved: iio: chemical: sps30_i2c: fix buffer size in sps30_... |
| CVE-2026-42946 | HIGH | 7.4 | 0.9% | May 13, 2026 | A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory... |
| CVE-2026-42945 | HIGH | 8.1 | 68.0% | May 13, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists w... |
| CVE-2026-42937 | HIGH | 7.1 | 0.2% | May 13, 2026 | Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and i... |
| CVE-2026-42930 | HIGH | 8.7 | 0.5% | May 13, 2026 | When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Applia... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now