2026 CVE Vulnerabilities

60,206 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41523HIGH7.5vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security chec...
CVE-2026-56698MEDIUM6.1Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 fail to validate script-capable URLs in the navigateTo open optio...
CVE-2026-56697MEDIUM6.1Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 accept protocol-relative paths such as //evil.com in the reloadNu...
CVE-2026-56357MEDIUM5.3n8n before 1.123.15 and 2.5.0 contains a webhook forgery vulnerability in the GitHub Webhook Trigger node that fails to ...
CVE-2026-56348CRITICAL9.9n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options end...
CVE-2026-56326MEDIUM6.1Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 contain a server-side open redirect vulnerability in navigateTo t...
CVE-2026-56324HIGH8.8Capgo before 12.128.2 contains a rate limit bypass vulnerability in the channel_self endpoint that allows attackers to c...
CVE-2026-56323HIGH8.7Capgo before 12.128.2 contains an information disclosure vulnerability in the /functions/v1/channel_self endpoint that a...
CVE-2026-56321MEDIUM6.9Capgo (backend Supabase edge functions) before 12.128.2 does not apply the global authentication middleware to the GET /...
CVE-2026-56314HIGH7.1Capgo before 12.128.12 fails to filter deleted app versions when joining channels during /updates resolution, allowing d...
CVE-2026-56311MEDIUM6.9Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.get_current_plan_max_org RPC function...
CVE-2026-56306MEDIUM6.4Capgo before 12.128.2 contains a weak parsing vulnerability in the x-limited-key-id header that allows attackers to bypa...
CVE-2026-56280HIGH7.1Cap-go before 12.128.2 contains a privilege inversion vulnerability in GET /build/logs/:jobId that allows read-only API ...
CVE-2026-56268HIGH7.7Flowise before 3.1.2 contains an information disclosure vulnerability in the /api/v1/chatflows/apikey/:apikey endpoint. ...
CVE-2026-56266HIGH8.6Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm e...
CVE-2026-56255MEDIUM5.3Capgo before 12.128.2 contains a denial of service vulnerability in the POST /app/demo endpoint that allows authenticate...
CVE-2026-56221HIGH7.1Cap-go before 12.128.2 contains multiple SQL injection vulnerabilities in cloudflare.ts where user-controlled values fro...
CVE-2026-55409HIGH7.6Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.53, a disabl...
CVE-2026-54911MEDIUM6.5UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.13.0, ujson.dum...
CVE-2026-54281HIGH8.7Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.24, an authentication bypass v...
CVE-2026-48517HIGH7.5MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's typeless deseria...
CVE-2026-48516HIGH7.5MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, InterfaceLookupFormatter<TKey,TElemen...
CVE-2026-48515HIGH7.5MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's multi-dimensiona...
CVE-2026-48514HIGH7.5MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, UnsafeBlitFormatterBase<T>.Deserializ...
CVE-2026-48513HIGH7.5MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, runtime-generated union deserializers...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now