2026 CVE Vulnerabilities

53,128 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-59921MEDIUM6.5Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ...
CVE-2026-54719HIGH7.5goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown....
CVE-2026-54659MEDIUM6.9Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18...
CVE-2026-54658CRITICAL9.8Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.5.1, escapeValue() in packages/clickhouse/src/core/u...
CVE-2026-54650HIGH8.6openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/publ...
CVE-2026-54638HIGH7.5gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted...
CVE-2026-47219HIGH7.5find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and w...
CVE-2026-55415HIGH7.5datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch...
CVE-2026-55403LOW3.7datamodel-code-generator generates Python data models from schema definitions. Prior to 0.63.0, src/datamodel_code_gener...
CVE-2026-55391HIGH7.5datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch...
CVE-2026-55390HIGH7.5datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema pars...
CVE-2026-55389HIGH7.5datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch...
CVE-2026-54691HIGH8.2datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_co...
CVE-2026-54690HIGH8.2datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch...
CVE-2026-54656HIGH7.8datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch...
CVE-2026-54655HIGH7.8datamodel-code-generator generates Python data models from schema definitions. From 0.51.0 until 0.60.2, x-python-type v...
CVE-2026-54654HIGH7.8datamodel-code-generator generates Python data models from schema definitions. From 0.14.1 until 0.60.2, the --extra-tem...
CVE-2026-54653HIGH8.8datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch...
CVE-2026-54621HIGH7.8datamodel-code-generator generates Python data models from schema definitions. Prior to 0.60.1, GraphQL Union descriptio...
CVE-2026-6881CRITICAL9.4A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated a...
CVE-2026-59943MEDIUM5.3Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted con...
CVE-2026-59942HIGH7.5Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack v...
CVE-2026-59941HIGH7.5Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PN...
CVE-2026-56722MEDIUM5.3Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can byp...
CVE-2026-49447MEDIUM5.3Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now