2026 CVE Vulnerabilities

56,949 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-44979MEDIUM6.3@hapi/wreck is an HTTP client utility. Prior to 18.1.1, when @hapi/wreck follows a 3xx redirect to a different hostname,...
CVE-2026-55518CRITICAL9.6Avo is a framework to create admin panels for Ruby on Rails apps. Prior to 3.32.1 and 4.0.0.beta.51, Avo's association a...
CVE-2026-54498HIGH8.7view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4...
CVE-2026-54497MEDIUM6.8view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 4...
CVE-2026-54490MEDIUM6.3websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, if this library is used with the pe...
CVE-2026-54466HIGH7.5websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions ...
CVE-2026-54244LOW3.5Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.0 and 6.20.3, the Live Preview endp...
CVE-2026-54243MEDIUM6.1Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, form submission valu...
CVE-2026-54242MEDIUM4.9Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, the Glide image prox...
CVE-2026-54163MEDIUM4.7secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds th...
CVE-2026-54159CRITICAL10PrestaShop ps_facetedsearch is a module that adds layered navigation filters. From 3.0.0 until 4.0.4, the ps_facetedsear...
CVE-2026-53727HIGH8.6css_parser is a Ruby CSS parser. From 2.2.0 until 3.0.0, CssParser::Parser#read_remote_file in lib/css_parser/parser.rb,...
CVE-2026-52584HIGH7.1Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a local attacker to obtain sensitive information via ...
CVE-2026-52348CRITICAL9.8cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java.
CVE-2026-52203HIGH7.5An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source parameter.
CVE-2026-50274HIGH7.5Datadog dd-trace-go is a Go client library for Datadog application performance monitoring, profiling, and security monit...
CVE-2026-50272HIGH7.5dd-trace is the Datadog APM client for Node.js. Prior to 5.100.0, W3C baggage propagation in packages/dd-trace/src/bagga...
CVE-2026-50271HIGH7.5Datadog dd-trace-py is the Datadog Python APM client. Prior to 4.8.2, Datadog tracing libraries that implement W3C bagga...
CVE-2026-49977MEDIUM4.3tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.33.0, tarteaucitron.cookie.purge() is called on...
CVE-2026-48062CRITICAL9.8CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/St...
CVE-2026-45785MEDIUM6.2OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Sto...
CVE-2026-45784HIGH7.1rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::ciph...
CVE-2026-44891HIGH7.5Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2...
CVE-2026-16074MEDIUM6.3A vulnerability was detected in AstrBotDevs AstrBot up to 4.25.2. This affects the function update_plugin/update_all_plu...
CVE-2026-13446CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now