2026 CVE Vulnerabilities

57,068 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-56283MEDIUM5.4Capgo before 12.128.2 contains an html injection vulnerability in the organization settings endpoint that allows attacke...
CVE-2026-56273MEDIUM6.5Flowise before 3.1.0 contains a path traversal vulnerability in Faiss and SimpleStore vector store implementations that ...
CVE-2026-56250HIGH8.7Capgo before 12.128.2 allows upload-scoped API keys to modify the mutable app_versions.r2_path field through PostgREST, ...
CVE-2026-56246HIGH8.1Capgo before 12.128.2 contains a broken access control vulnerability in the organization management API where a scoped A...
CVE-2026-56226HIGH8.7Capgo (Cap-go/capgo) before 12.128.2 exposes the Supabase PostgREST RPC function public.get_orgs_v6(userid uuid), which ...
CVE-2026-56220HIGH7.1Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.manifest INSERT policy that allows re...
CVE-2026-56217MEDIUM5.3Capgo before 12.128.2 contains a policy bypass vulnerability in app_versions update enforcement that allows app-scoped A...
CVE-2026-56086HIGH8.8Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-54061CRITICAL9.1Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for e...
CVE-2026-53482HIGH7.5Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-53480LOW2.7Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-44840HIGH7.5Dgraph is an open source distributed GraphQL database. Prior to version 25.3.4, the `checkUserPassword` GraphQL query in...
CVE-2026-41122HIGH7.1Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-22927HIGH7.8Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.
CVE-2026-15053HIGH7.5Tanium addressed a denial of service vulnerability in Tanium Server.
CVE-2026-15035HIGH7.8A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm...
CVE-2026-15034MEDIUM4.3A vulnerability has been found in flask-dashboard Flask-MonitoringDashboard up to 5.0.2. Affected by this issue is some ...
CVE-2026-15033MEDIUM6.3A flaw has been found in christopherthielen check-peer-dependencies up to 4.3.4. Affected by this vulnerability is the f...
CVE-2026-8315MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Desig...
CVE-2026-8310MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Desig...
CVE-2026-8307CRITICAL9.8Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Desig...
CVE-2026-6820HIGH7.2The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ema...
CVE-2026-6740MEDIUM6.4The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Stored Cro...
CVE-2026-6459MEDIUM6.4The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored ...
CVE-2026-5459MEDIUM5.3The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now