2026 CVE Vulnerabilities

59,349 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-54898LOW2.1Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2,Oj::Parse...
CVE-2026-54897LOW2.1Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to 3.17.2, Oj::Doc iterators (e...
CVE-2026-54896LOW2.1Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, when in ...
CVE-2026-54592HIGH7.5Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj::Doc#...
CVE-2026-54502MEDIUM6.3Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.dump ...
CVE-2026-54500MEDIUM5.3Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj.load ...
CVE-2026-57995HIGH8.8phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that allows GR...
CVE-2026-56777MEDIUM5.3n8n before 2.25.7 and 2.26.x before 2.26.2 contains an abstract syntax tree (AST) security validator bypass in the Pytho...
CVE-2026-56700CRITICAL9.8Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Sch...
CVE-2026-56415CRITICAL10Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable...
CVE-2026-56413CRITICAL10Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens ...
CVE-2026-56399MEDIUM5.3Open WebUI before 0.6.27 contains a server-side request forgery vulnerability in the /api/v1/retrieval/process/web endpo...
CVE-2026-56377MEDIUM4.8ImageMagick before 7.1.2-24 contains an incorrect policy check that allows attackers to create or truncate files disallo...
CVE-2026-56369MEDIUM6.3ImageMagick before 7.1.2-22 contains an information disclosure vulnerability in the PasskeyEncipherImage method due to A...
CVE-2026-56365MEDIUM5.3ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers c...
CVE-2026-56364LOW1.9ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing ma...
CVE-2026-56363MEDIUM4.8ImageMagick before 7.1.2-22 contains a division by zero vulnerability in binomial kernel processing that allows attacker...
CVE-2026-56361HIGH7.1ImageMagick before 7.1.2-19 contains an off-by-one error in morphology validation allowing out-of-bounds heap buffer rea...
CVE-2026-56356MEDIUM5.4n8n contains a stored cross-site scripting vulnerability in the Chat Trigger node's Custom CSS field due to a misconfigu...
CVE-2026-56350HIGH7.7n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable SSO enforce...
CVE-2026-56334MEDIUM5.3Capgo before 12.128.2 lacks an UPDATE row-level security policy for the build_requests table, preventing API-key and ano...
CVE-2026-56333MEDIUM5.3Capgo before 12.128.2 contains a server-side validation bypass vulnerability in organization security settings that allo...
CVE-2026-56331MEDIUM6.9Capgo before 12.128.2 contains improper error handling in the /private/accept_invitation endpoint that returns HTTP 500 ...
CVE-2026-56328HIGH7.1Capgo before 12.128.2 allows multiple public channels for the same app and platform to coexist simultaneously, while unn...
CVE-2026-56327MEDIUM6.9Capgo before 12.128.2 contains an information disclosure vulnerability in the public.invite_user_to_org RPC function tha...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now