2026 CVE Vulnerabilities

61,018 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-12774MEDIUM6.3A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the functi...
CVE-2026-12773CRITICAL9.8A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file lite...
CVE-2026-12772MEDIUM6.3A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticate_user of the ...
CVE-2026-12771HIGH7.5A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/pro...
CVE-2026-12770HIGH8.8A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file ...
CVE-2026-56355LOW3.7GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.
CVE-2026-56347MEDIUM6.1AVideo TopMenu plugin through version 26.0 contains a stored cross-site scripting vulnerability in menu item rendering d...
CVE-2026-56346MEDIUM6.9AVideo through version 25.0 contains an authentication bypass vulnerability in the decryptMessage.json.php endpoint that...
CVE-2026-56345CRITICAL9.2AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php end...
CVE-2026-56342MEDIUM6.8AVideo through version 27.0 contains a server-side request forgery vulnerability in plugin/Live/test.php that allows aut...
CVE-2026-56341HIGH8.7AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authori...
CVE-2026-56340HIGH7.5vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because P...
CVE-2026-5366CRITICAL9.9Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `...
CVE-2026-56332MEDIUM5.1Capgo before 12.128.2 contains an open redirect vulnerability in the confirm-signup endpoint that allows attackers to re...
CVE-2026-56330MEDIUM4.8Capgo before 12.128.2 contains an open redirect vulnerability in stripe_portal and stripe_checkout endpoints that accept...
CVE-2026-56325LOW3.1Capgo before 12.128.2 uses ILIKE pattern matching instead of exact matching for app_id lookup in the preview subdomain r...
CVE-2026-56319MEDIUM5.3Capgo before 12.128.2 contains an information disclosure vulnerability in the GET /statistics/app/:app_id endpoint that ...
CVE-2026-56317MEDIUM6.1Nuxt before 4.4.7 (and the 3.x branch before 3.21.7) contains a cross-site scripting vulnerability in the NoScript compo...
CVE-2026-56307MEDIUM5.3Cap-go before 12.128.12 contains a broken cursor pagination vulnerability in the /private/devices endpoint on the Cloudf...
CVE-2026-56304MEDIUM6.9picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to cr...
CVE-2026-56295MEDIUM6.3Capgo before 12.128.2 contains an authorization bypass vulnerability in webhook management endpoints that allows non-exp...
CVE-2026-56294MEDIUM4.8capacitor-native-biometric before 12.128.2 contains an authentication bypass vulnerability where the onAuthenticationSuc...
CVE-2026-56282MEDIUM6.9Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /replication endpoint that...
CVE-2026-56276MEDIUM6Flowise before 3.1.2 contains a mass assignment vulnerability in the PUT /api/v1/user endpoint that allows authenticated...
CVE-2026-56267MEDIUM6.9Flowise before 3.0.13 contains an information exposure vulnerability in the POST /api/v1/account/forgot-password endpoin...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now