2026 CVE Vulnerabilities

64,868 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-19780HIGH8.8Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi...
CVE-2026-18111HIGH8.5Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image...
CVE-2026-18110HIGH7.5Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint ...
CVE-2026-91990HIGH7.5Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart da...
CVE-2026-91989HIGH7.5atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote...
CVE-2026-91988HIGH8.1atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowin...
CVE-2026-91985HIGH7.5Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allo...
CVE-2026-91973HIGH7.5Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiti...
CVE-2026-91972HIGH7.5Vikunja versions before 2.6.0 fail to apply rate limiting to /api/v2 public authentication endpoints including login, re...
CVE-2026-91965HIGH7.5WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/cale...
CVE-2026-91964HIGH8.8FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Ser...
CVE-2026-91955HIGH7.5FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, al...
CVE-2026-91948HIGH7.5FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handli...
CVE-2026-91947HIGH7.5FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a c...
CVE-2026-91943HIGH7.7Crawl4AI before 0.9.3 contains a server-side request forgery vulnerability in PDFContentScrapingStrategy where _get_pdf_...
CVE-2026-91941HIGH7.5Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that all...
CVE-2026-91940HIGH7.5crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_unt...
CVE-2026-91938HIGH7.1Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer ...
CVE-2026-91937HIGH7.5Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within ...
CVE-2026-91935HIGH8.3Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect ...
CVE-2026-91934HIGH8.8Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite datab...
CVE-2026-91933HIGH7.1Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authen...
CVE-2026-91932HIGH8.5Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attac...
CVE-2026-91931HIGH8.5Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated att...
CVE-2026-91930HIGH7.5Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now