2026 CVE Vulnerabilities

60,206 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-12969MEDIUM5.3An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section re...
CVE-2026-11772MEDIUM5.1DRIMO CMS is vulnerable to Reflected XSS via q parameter in searching functionality. An attacker can prepare an URL that...
CVE-2026-10609MEDIUM6.8A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards Serv...
CVE-2026-56784HIGH8.6OpenRemote before 1.25.0 contains an insecure direct object reference (IDOR) vulnerability in the bulk alarm deletion en...
CVE-2026-56762MEDIUM6.9Hono before 4.12.12 does not validate cookie names on the write path in the setCookie(), serialize(), and serializeSigne...
CVE-2026-56701HIGH7.1Grav before 2.0.0-beta.2 contains an XML external entity injection vulnerability in SVG file upload processing that allo...
CVE-2026-56379CRITICAL9.2ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows atta...
CVE-2026-56376LOW3.3ImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-free in the meta coder: when memory allocation fails...
CVE-2026-56371MEDIUM5.3ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture ...
CVE-2026-56322HIGH8.7Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /updates endpoint that res...
CVE-2026-56315CRITICAL9.8picklescan before 1.0.4 fails to block at least seven Python standard library modules (including uuid, _osx_support, _ai...
CVE-2026-56301MEDIUM6.8Nuxt 4.0.0 before 4.4.7 and 3.18.0 before 3.21.7, when running the development server (nuxt dev) on Linux, binds the vit...
CVE-2026-56275HIGH7.1Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows attackers...
CVE-2026-56274CRITICAL9.9Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to inco...
CVE-2026-56263MEDIUM6.1Crawl4AI before 0.8.7 contains a stored cross-site scripting vulnerability in the monitor dashboard that renders crawl U...
CVE-2026-56258CRITICAL9.2Crawl4AI before 0.8.8 contains an arbitrary file write vulnerability in the screenshot and PDF endpoints that allows una...
CVE-2026-56248HIGH8.7Cap-go capgo (capgo-backend) before 12.128.12 contains an unauthenticated denial-of-service vulnerability arising from t...
CVE-2026-56243HIGH8.6Capgo before 12.128.2 contains a security control bypass vulnerability where the PostgREST/RLS plane accepts plaintext A...
CVE-2026-56234MEDIUM6.9Capgo before 12.128.2 contains a credential validation vulnerability in the POST /functions/v1/private/validate_password...
CVE-2026-56225HIGH8.7Capgo before 12.128.2 contains an authorization bypass vulnerability in its public API key management handlers (get/put/...
CVE-2026-56222HIGH8.6Capgo before 12.128.2 contains an authorization bypass vulnerability in POST /private/role_bindings that fails to verify...
CVE-2026-54892HIGH8.7Inefficient algorithmic complexity in Plug's nested-parameter decoder allows an unauthenticated remote attacker to cause...
CVE-2026-4610MEDIUM6.4The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2026-44089CRITICAL9.4Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality in cgi-bin/cstecgi.cgi endpoint. Thi...
CVE-2026-10857MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in AKIN Software Comp...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now