2026 CVE Vulnerabilities
60,215 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12771 | HIGH | 7.5 | 0.3% | Jun 21, 2026 | A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/pro... |
| CVE-2026-12770 | HIGH | 8.8 | 0.3% | Jun 21, 2026 | A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file ... |
| CVE-2026-56355 | LOW | 3.7 | 0.3% | Jun 20, 2026 | GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization. |
| CVE-2026-56347 | MEDIUM | 6.1 | 0.2% | Jun 20, 2026 | AVideo TopMenu plugin through version 26.0 contains a stored cross-site scripting vulnerability in menu item rendering d... |
| CVE-2026-56346 | MEDIUM | 6.9 | 0.4% | Jun 20, 2026 | AVideo through version 25.0 contains an authentication bypass vulnerability in the decryptMessage.json.php endpoint that... |
| CVE-2026-56345 | CRITICAL | 9.2 | 0.3% | Jun 20, 2026 | AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php end... |
| CVE-2026-56342 | MEDIUM | 6.8 | 0.2% | Jun 20, 2026 | AVideo through version 27.0 contains a server-side request forgery vulnerability in plugin/Live/test.php that allows aut... |
| CVE-2026-56341 | HIGH | 8.7 | 0.3% | Jun 20, 2026 | AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authori... |
| CVE-2026-56340 | HIGH | 7.5 | 0.4% | Jun 20, 2026 | vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because P... |
| CVE-2026-5366 | CRITICAL | 9.9 | 0.6% | Jun 20, 2026 | Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `... |
| CVE-2026-56332 | MEDIUM | 5.1 | 0.2% | Jun 20, 2026 | Capgo before 12.128.2 contains an open redirect vulnerability in the confirm-signup endpoint that allows attackers to re... |
| CVE-2026-56330 | MEDIUM | 4.8 | 0.2% | Jun 20, 2026 | Capgo before 12.128.2 contains an open redirect vulnerability in stripe_portal and stripe_checkout endpoints that accept... |
| CVE-2026-56325 | LOW | 3.1 | 0.2% | Jun 20, 2026 | Capgo before 12.128.2 uses ILIKE pattern matching instead of exact matching for app_id lookup in the preview subdomain r... |
| CVE-2026-56319 | MEDIUM | 5.3 | 0.2% | Jun 20, 2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in the GET /statistics/app/:app_id endpoint that ... |
| CVE-2026-56317 | MEDIUM | 6.1 | 0.2% | Jun 20, 2026 | Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript compo... |
| CVE-2026-56307 | MEDIUM | 5.3 | 0.2% | Jun 20, 2026 | Cap-go before 12.128.12 contains a broken cursor pagination vulnerability in the /private/devices endpoint on the Cloudf... |
| CVE-2026-56304 | MEDIUM | 6.9 | 0.3% | Jun 20, 2026 | picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to cr... |
| CVE-2026-56295 | MEDIUM | 6.3 | 0.2% | Jun 20, 2026 | Capgo before 12.128.2 contains an authorization bypass vulnerability in webhook management endpoints that allows non-exp... |
| CVE-2026-56294 | MEDIUM | 4.8 | 0.2% | Jun 20, 2026 | capacitor-native-biometric before 12.128.2 contains an authentication bypass vulnerability where the onAuthenticationSuc... |
| CVE-2026-56282 | MEDIUM | 6.9 | 0.2% | Jun 20, 2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /replication endpoint that... |
| CVE-2026-56276 | MEDIUM | 6 | 0.3% | Jun 20, 2026 | Flowise before 3.1.2 contains a mass assignment vulnerability in the PUT /api/v1/user endpoint that allows authenticated... |
| CVE-2026-56267 | MEDIUM | 6.9 | 0.3% | Jun 20, 2026 | Flowise before 3.0.13 contains an information exposure vulnerability in the POST /api/v1/account/forgot-password endpoin... |
| CVE-2026-56235 | MEDIUM | 6.9 | 0.3% | Jun 20, 2026 | Cap-go capgo before 12.128.2 contains an authorization bypass in several Supabase PostgREST RPC functions (get_app_metri... |
| CVE-2026-56228 | MEDIUM | 6.9 | 0.3% | Jun 20, 2026 | Capgo before 12.128.2 fails to enforce a maximum value on the minimum password length field in its password policy confi... |
| CVE-2026-56227 | MEDIUM | 5.4 | 0.2% | Jun 20, 2026 | Capgo before 12.128.2 contains a server-side request forgery vulnerability in webhook URL validation that allows loopbac... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now