2026 CVE Vulnerabilities

43,380 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-13190HIGH8.1In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities all...
CVE-2026-13189HIGH7.5In Progress® Telerik® UI for AJAX prior to v2026.2.708, insufficient validation of the language parameter in the spell c...
CVE-2026-13187HIGH8.1In Progress® Telerik® UI for AJAX prior to v2026.2.708, DialogHandler provider type input may be tampered with, potentia...
CVE-2026-13186HIGH8.1In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence sto...
CVE-2026-13185HIGH8.1In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager...
CVE-2026-13184HIGH7.5In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKe...
CVE-2026-13183HIGH7.5In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic...
CVE-2026-13182HIGH7.5In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt f...
CVE-2026-13181HIGH8.1In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName process...
CVE-2026-44191HIGH7.8A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) a...
CVE-2026-65603HIGH8.8The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated pr...
CVE-2026-65602HIGH8.8Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRo...
CVE-2026-65598HIGH7.5n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows a...
CVE-2026-65596HIGH8.1n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based cr...
CVE-2026-65595HIGH8.8n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange module regardle...
CVE-2026-65591HIGH8.8n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authentic...
CVE-2026-65016HIGH8.8n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance...
CVE-2026-65015HIGH8.8n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-executio...
CVE-2026-61391HIGH7.2There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers ...
CVE-2026-61390HIGH7.7There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to ca...
CVE-2026-57600HIGH7.5Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers t...
CVE-2026-4773HIGH8.1Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA allows Authenticati...
CVE-2026-44190HIGH7.8A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) a...
CVE-2026-44189HIGH7.8A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injec...
CVE-2026-14551HIGH8.8The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are v...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now