2026 CVE Vulnerabilities

56,949 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-16088MEDIUM4.7A vulnerability was detected in halo-dev halo up to 2.24.2. Affected by this vulnerability is the function Download of t...
CVE-2026-16085MEDIUM5.3A security vulnerability has been detected in Sipeed PicoClaw up to 0.2.9. Affected is the function NewContextBuilder of...
CVE-2026-47871HIGH8.8VMware Avi Load Balancer contains a directory traversal vulnerability. Flaws in file path validation allow malicious, au...
CVE-2026-47870HIGH8.8VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with network acce...
CVE-2026-47869HIGH8.8VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network acc...
CVE-2026-47868HIGH7.8VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local access may be ...
CVE-2026-47867HIGH8.8VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be abl...
CVE-2026-47866HIGH8.3VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a l...
CVE-2026-47865CRITICAL9.8VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be ab...
CVE-2026-16084HIGH7.3A weakness has been identified in Sipeed PicoClaw up to 0.2.9. This impacts the function web_fetch of the file pkg/tools...
CVE-2026-16083MEDIUM5.5A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. This affects the function webhook.ParseRequest of th...
CVE-2026-16082MEDIUM5.3A vulnerability was identified in Sipeed PicoClaw up to 0.2.9. The impacted element is the function ExecTool.executeRun ...
CVE-2026-16081MEDIUM4.3A vulnerability was determined in Sipeed PicoClaw up to 0.2.9. The affected element is an unknown function of the file w...
CVE-2026-16077MEDIUM5.3A vulnerability was found in AstrBotDevs AstrBot up to 4.25.5. Impacted is the function _normalize_rw_path of the file a...
CVE-2026-16076MEDIUM6.3A vulnerability has been found in AstrBotDevs AstrBot up to 4.25.5. This issue affects the function OpenApiRoute.chat_se...
CVE-2026-9734MEDIUM4.3The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, a...
CVE-2026-16075MEDIUM4.3A flaw has been found in AstrBotDevs AstrBot up to 4.25.5. This vulnerability affects the function OpenApiRoute.get_chat...
CVE-2026-57980MEDIUM5.4Authentication bypass using an alternate path or channel in Microsoft Edge (Chromium-based) allows an unauthorized attac...
CVE-2026-56741HIGH7.5JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote...
CVE-2026-56740HIGH7.5JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote...
CVE-2026-56171HIGH7.5Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disc...
CVE-2026-54335LOW3.7Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In 5.0.44 and ...
CVE-2026-49485HIGH7.5HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.9 ...
CVE-2026-48049MEDIUM5.3@hapi/inert provides static file and directory handlers for hapi.js. From 4.0.0 to 7.1.0, @hapi/inert serves static file...
CVE-2026-48022MEDIUM6.5@hapi/wreck is an HTTP client utility. Prior to 18.1.2, Wreck strips credential headers including Authorization, Cookie,...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now