2026 CVE Vulnerabilities

43,288 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-12144HIGH8.8The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and incl...
CVE-2026-56822HIGH7.4Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ...
CVE-2026-56821HIGH7.4Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ...
CVE-2026-54719HIGH7.5goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown....
CVE-2026-54650HIGH8.6openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/publ...
CVE-2026-54638HIGH7.5gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted...
CVE-2026-47219HIGH7.5find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and w...
CVE-2026-55415HIGH7.5datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch...
CVE-2026-55391HIGH7.5datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch...
CVE-2026-55390HIGH7.5datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema pars...
CVE-2026-55389HIGH7.5datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch...
CVE-2026-54691HIGH8.2datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_co...
CVE-2026-54690HIGH8.2datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch...
CVE-2026-54656HIGH7.8datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch...
CVE-2026-54655HIGH7.8datamodel-code-generator generates Python data models from schema definitions. From 0.51.0 until 0.60.2, x-python-type v...
CVE-2026-54654HIGH7.8datamodel-code-generator generates Python data models from schema definitions. From 0.14.1 until 0.60.2, the --extra-tem...
CVE-2026-54653HIGH8.8datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch...
CVE-2026-54621HIGH7.8datamodel-code-generator generates Python data models from schema definitions. Prior to 0.60.1, GraphQL Union descriptio...
CVE-2026-59942HIGH7.5Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack v...
CVE-2026-59941HIGH7.5Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PN...
CVE-2026-15328HIGH8.1IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 i...
CVE-2026-15325HIGH8.7IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling ...
CVE-2026-15280HIGH7.5IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segm...
CVE-2026-15064HIGH8.7IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 i...
CVE-2026-15057HIGH7.5IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontr...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now