2026 CVE Vulnerabilities
60,206 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-41523 | HIGH | 7.5 | 0.9% | Jun 22, 2026 | vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security chec... |
| CVE-2026-56698 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 fail to validate script-capable URLs in the navigateTo open optio... |
| CVE-2026-56697 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 accept protocol-relative paths such as //evil.com in the reloadNu... |
| CVE-2026-56357 | MEDIUM | 5.3 | 0.2% | Jun 22, 2026 | n8n before 1.123.15 and 2.5.0 contains a webhook forgery vulnerability in the GitHub Webhook Trigger node that fails to ... |
| CVE-2026-56348 | CRITICAL | 9.9 | 0.3% | Jun 22, 2026 | n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options end... |
| CVE-2026-56326 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 contain a server-side open redirect vulnerability in navigateTo t... |
| CVE-2026-56324 | HIGH | 8.8 | 0.3% | Jun 22, 2026 | Capgo before 12.128.2 contains a rate limit bypass vulnerability in the channel_self endpoint that allows attackers to c... |
| CVE-2026-56323 | HIGH | 8.7 | 0.4% | Jun 22, 2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in the /functions/v1/channel_self endpoint that a... |
| CVE-2026-56321 | MEDIUM | 6.9 | 0.3% | Jun 22, 2026 | Capgo (backend Supabase edge functions) before 12.128.2 does not apply the global authentication middleware to the GET /... |
| CVE-2026-56314 | HIGH | 7.1 | 0.3% | Jun 22, 2026 | Capgo before 12.128.12 fails to filter deleted app versions when joining channels during /updates resolution, allowing d... |
| CVE-2026-56311 | MEDIUM | 6.9 | 0.3% | Jun 22, 2026 | Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.get_current_plan_max_org RPC function... |
| CVE-2026-56306 | MEDIUM | 6.4 | 0.3% | Jun 22, 2026 | Capgo before 12.128.2 contains a weak parsing vulnerability in the x-limited-key-id header that allows attackers to bypa... |
| CVE-2026-56280 | HIGH | 7.1 | 0.3% | Jun 22, 2026 | Cap-go before 12.128.2 contains a privilege inversion vulnerability in GET /build/logs/:jobId that allows read-only API ... |
| CVE-2026-56268 | HIGH | 7.7 | 0.3% | Jun 22, 2026 | Flowise before 3.1.2 contains an information disclosure vulnerability in the /api/v1/chatflows/apikey/:apikey endpoint. ... |
| CVE-2026-56266 | HIGH | 8.6 | 0.3% | Jun 22, 2026 | Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm e... |
| CVE-2026-56255 | MEDIUM | 5.3 | 0.3% | Jun 22, 2026 | Capgo before 12.128.2 contains a denial of service vulnerability in the POST /app/demo endpoint that allows authenticate... |
| CVE-2026-56221 | HIGH | 7.1 | 0.3% | Jun 22, 2026 | Cap-go before 12.128.2 contains multiple SQL injection vulnerabilities in cloudflare.ts where user-controlled values fro... |
| CVE-2026-55409 | HIGH | 7.6 | 0.2% | Jun 22, 2026 | Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.53, a disabl... |
| CVE-2026-54911 | MEDIUM | 6.5 | 0.3% | Jun 22, 2026 | UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.13.0, ujson.dum... |
| CVE-2026-54281 | HIGH | 8.7 | 0.3% | Jun 22, 2026 | Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.24, an authentication bypass v... |
| CVE-2026-48517 | HIGH | 7.5 | 0.2% | Jun 22, 2026 | MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's typeless deseria... |
| CVE-2026-48516 | HIGH | 7.5 | 0.2% | Jun 22, 2026 | MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, InterfaceLookupFormatter<TKey,TElemen... |
| CVE-2026-48515 | HIGH | 7.5 | 0.2% | Jun 22, 2026 | MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's multi-dimensiona... |
| CVE-2026-48514 | HIGH | 7.5 | 0.2% | Jun 22, 2026 | MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, UnsafeBlitFormatterBase<T>.Deserializ... |
| CVE-2026-48513 | HIGH | 7.5 | 0.2% | Jun 22, 2026 | MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, runtime-generated union deserializers... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now