2026 CVE Vulnerabilities

60,206 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-12958HIGH8.5Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust ...
CVE-2026-12957HIGH8.5Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may all...
CVE-2026-11940HIGH7.8tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink reference...
CVE-2026-56696MEDIUM5.4OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel sende...
CVE-2026-56695HIGH7.1OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote ...
CVE-2026-56694MEDIUM5.4NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration approval flow where hand...
CVE-2026-56693MEDIUM6.8NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that pe...
CVE-2026-56692MEDIUM6.8NanoClaw before 2.1.17 contains a symlink following vulnerability in forwardAttachedFiles that allows container-controll...
CVE-2026-56402HIGH7.1NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails ...
CVE-2026-55767MEDIUM5.8Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain a...
CVE-2026-55766MEDIUM4.8guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject C...
CVE-2026-55568MEDIUM5.9Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by...
CVE-2026-54314HIGH7.5n8n is an open source workflow automation platform. Prior to 2.24.0, the Compression node's Decompress operation expande...
CVE-2026-54313HIGH7.7n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with workflow edit access cou...
CVE-2026-54312HIGH8.5n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with permission to create or ...
CVE-2026-54311HIGH7.7n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to...
CVE-2026-54310CRITICAL9.9n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to...
CVE-2026-54309CRITICAL10n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run in HTTP tra...
CVE-2026-54303MEDIUM5.4n8n is an open source workflow automation platform. Prior to 2.24.0, an endpoint in the Meta and Microsoft Teams trigger...
CVE-2026-52673MEDIUM6.5SQL Injection vulnerability in Cboard v.0.4.2 and before allows a remote attacker to execute arbitrary code via the getD...
CVE-2026-56815HIGH7.4pwnlift before d7a9544, in a privileged deployment, contains a symlink following vulnerability in the upload handler in ...
CVE-2026-35019CRITICAL9.2NetComm NF20MESH routers running firmware R6B031 and earlier contain an authentication bypass vulnerability that allows ...
CVE-2026-35018HIGH8.8NetComm NF20MESH routers running firmware R6B031 and earlier contain an authenticated remote code execution vulnerabilit...
CVE-2026-28496CRITICAL9.4FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Temp...
CVE-2026-27604CRITICAL10FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now