2026 CVE Vulnerabilities

57,064 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-60125MEDIUM5.3MISP’s importModule() path used getEnabledModule() to resolve a single import module by name, but this lookup did not en...
CVE-2026-60124MEDIUM5.3An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys wit...
CVE-2026-60092MEDIUM6.1AVideo (Meet plugin) through commit e8d6119f3cb1b849149906efeb0a41fc024f59f8 contains a stored cross-site scripting vuln...
CVE-2026-59257HIGH8.8n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the legacy My...
CVE-2026-59253MEDIUM5n8n before 2.28.0 contains an improper authorization vulnerability allowing authenticated users to assign workflows to f...
CVE-2026-58657MEDIUM4.8Grav before 2.0.0 (affected through 2.0.0-rc.9 and the 2.0 branch) contains a stored CSS injection vulnerability in the ...
CVE-2026-58656HIGH8.7Grav API plugin before v1.0.0-rc.16 accepts JWT tokens via the ?token= URL query parameter and responds with Access-Cont...
CVE-2026-58654MEDIUM5.3The Grav API plugin (getgrav/grav-plugin-api) 1.0.0 contains an unrestricted file upload vulnerability in the avatar upl...
CVE-2026-58480CRITICAL9.8Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability...
CVE-2026-56778MEDIUM6.4n8n before 2.25.7 and 2.26.x before 2.26.2 contains an authorization bypass in the Public API execution retry endpoint, ...
CVE-2026-56776HIGH7.4n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypass in the POST /workflows/{workflowId}/test-runs/n...
CVE-2026-56775MEDIUM5.4n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization vulnerability in three mutating evaluation test-run en...
CVE-2026-56401Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-56374HIGH7.1ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary ch...
CVE-2026-56362MEDIUM4.2ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache...
CVE-2026-56360MEDIUM6.3n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger ...
CVE-2026-56359MEDIUM5.4n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management flow where authenticated use...
CVE-2026-56298MEDIUM5.3Capgo before 12.128.2 fails to strip EXIF metadata from images uploaded via the app information endpoint, exposing sensi...
CVE-2026-56297HIGH8.1FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcman_channel_close and dvcman_call_on_receive due to ...
CVE-2026-56293MEDIUM5.4Capgo before 12.128.2 contains an authorization flaw in transfer_app() that fails to update deploy_history.owner_org whe...
CVE-2026-56284MEDIUM6.9Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST RPC func...
CVE-2026-56283MEDIUM5.4Capgo before 12.128.2 contains an html injection vulnerability in the organization settings endpoint that allows attacke...
CVE-2026-56273MEDIUM6.5Flowise before 3.1.0 contains a path traversal vulnerability in Faiss and SimpleStore vector store implementations that ...
CVE-2026-56250HIGH8.7Capgo before 12.128.2 allows upload-scoped API keys to modify the mutable app_versions.r2_path field through PostgREST, ...
CVE-2026-56246HIGH8.1Capgo before 12.128.2 contains a broken access control vulnerability in the organization management API where a scoped A...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now