2026 CVE Vulnerabilities

50,995 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-44001HIGH8.6vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox escape vulnerability in vm2 v3.10.5 allows any ...
CVE-2026-44000HIGH7.2vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.0, a sandbox boundary violation in vm2 allows host object id...
CVE-2026-43998HIGH8.5vm2 is an open source vm/sandbox for Node.js. In 3.10.5, NodeVM's require.root path restriction can be bypassed using fi...
CVE-2026-0265HIGH8.1An authentication bypass vulnerability in Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with n...
CVE-2026-0237HIGH7.8An improper protection of alternate path vulnerability in Palo Alto Networks Prisma® Browser on macOS fails to properly ...
CVE-2026-44575HIGH7.5Next.js is a React framework for building full-stack web applications. From 15.2.0 to before 15.5.16 and 16.2.5, App Rou...
CVE-2026-44574HIGH8.1Next.js is a React framework for building full-stack web applications. From 15.4.0 to before 15.5.16 and 16.2.5, applica...
CVE-2026-44573HIGH7.5Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, Applica...
CVE-2026-6282HIGH8.6A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that ...
CVE-2026-6281HIGH8.8A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authentic...
CVE-2026-45740HIGH7.5protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.8 and 8.2.0, protobufjs could recu...
CVE-2026-45033HIGH7.8GitHub Copilot CLI brings AI-powered coding assistance directly to your command line. Prior to 1.0.43, a security vulne...
CVE-2026-44470HIGH7.8The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side...
CVE-2026-44432HIGH7.5urllib3 is an HTTP client library for Python. From 2.6.0 to before 2.7.0, urllib3 could decompress the whole response in...
CVE-2026-44295HIGH8.7protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbjs static code generation could e...
CVE-2026-44293HIGH8.8protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs generated ...
CVE-2026-44291HIGH8.1protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs used plain...
CVE-2026-44290HIGH7.5protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs allowed ce...
CVE-2026-44289HIGH7.5protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs could recu...
CVE-2026-43481HIGH7.8In the Linux kernel, the following vulnerability has been resolved: net-shapers: don't free reply skb after genlmsg_rep...
CVE-2026-43476HIGH7.8In the Linux kernel, the following vulnerability has been resolved: iio: chemical: sps30_i2c: fix buffer size in sps30_...
CVE-2026-42946HIGH7.4A vulnerability exists in the ngx_http_scgi_module and ngx_http_uwsgi_module modules that may result in excessive memory...
CVE-2026-42945HIGH8.1NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists w...
CVE-2026-42937HIGH7.1Incorrect permission assignment vulnerabilities exist in BIG-IP and BIG-IQ TMOS Shell (tmsh) arp and ndp commands, and i...
CVE-2026-42930HIGH8.7When running in Appliance mode, an authenticated attacker assigned the 'Administrator' role may be able to bypass Applia...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now