2026 CVE Vulnerabilities

60,215 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-12771HIGH7.5A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/pro...
CVE-2026-12770HIGH8.8A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file ...
CVE-2026-56355LOW3.7GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.
CVE-2026-56347MEDIUM6.1AVideo TopMenu plugin through version 26.0 contains a stored cross-site scripting vulnerability in menu item rendering d...
CVE-2026-56346MEDIUM6.9AVideo through version 25.0 contains an authentication bypass vulnerability in the decryptMessage.json.php endpoint that...
CVE-2026-56345CRITICAL9.2AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php end...
CVE-2026-56342MEDIUM6.8AVideo through version 27.0 contains a server-side request forgery vulnerability in plugin/Live/test.php that allows aut...
CVE-2026-56341HIGH8.7AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authori...
CVE-2026-56340HIGH7.5vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because P...
CVE-2026-5366CRITICAL9.9Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `...
CVE-2026-56332MEDIUM5.1Capgo before 12.128.2 contains an open redirect vulnerability in the confirm-signup endpoint that allows attackers to re...
CVE-2026-56330MEDIUM4.8Capgo before 12.128.2 contains an open redirect vulnerability in stripe_portal and stripe_checkout endpoints that accept...
CVE-2026-56325LOW3.1Capgo before 12.128.2 uses ILIKE pattern matching instead of exact matching for app_id lookup in the preview subdomain r...
CVE-2026-56319MEDIUM5.3Capgo before 12.128.2 contains an information disclosure vulnerability in the GET /statistics/app/:app_id endpoint that ...
CVE-2026-56317MEDIUM6.1Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript compo...
CVE-2026-56307MEDIUM5.3Cap-go before 12.128.12 contains a broken cursor pagination vulnerability in the /private/devices endpoint on the Cloudf...
CVE-2026-56304MEDIUM6.9picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to cr...
CVE-2026-56295MEDIUM6.3Capgo before 12.128.2 contains an authorization bypass vulnerability in webhook management endpoints that allows non-exp...
CVE-2026-56294MEDIUM4.8capacitor-native-biometric before 12.128.2 contains an authentication bypass vulnerability where the onAuthenticationSuc...
CVE-2026-56282MEDIUM6.9Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /replication endpoint that...
CVE-2026-56276MEDIUM6Flowise before 3.1.2 contains a mass assignment vulnerability in the PUT /api/v1/user endpoint that allows authenticated...
CVE-2026-56267MEDIUM6.9Flowise before 3.0.13 contains an information exposure vulnerability in the POST /api/v1/account/forgot-password endpoin...
CVE-2026-56235MEDIUM6.9Cap-go capgo before 12.128.2 contains an authorization bypass in several Supabase PostgREST RPC functions (get_app_metri...
CVE-2026-56228MEDIUM6.9Capgo before 12.128.2 fails to enforce a maximum value on the minimum password length field in its password policy confi...
CVE-2026-56227MEDIUM5.4Capgo before 12.128.2 contains a server-side request forgery vulnerability in webhook URL validation that allows loopbac...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now