2026 CVE Vulnerabilities
43,808 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-55608 | MEDIUM | 5.4 | 0.3% | Jul 15, 2026 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior... |
| CVE-2026-55410 | MEDIUM | 6.7 | 0.4% | Jul 15, 2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t... |
| CVE-2026-55399 | MEDIUM | 4.3 | 0.2% | Jul 15, 2026 | CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with vali... |
| CVE-2026-52888 | MEDIUM | 6.8 | 0.3% | Jul 15, 2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.... |
| CVE-2026-38753 | MEDIUM | 4.9 | 0.3% | Jul 15, 2026 | A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Serv... |
| CVE-2026-33684 | MEDIUM | 5.3 | 0.3% | Jul 15, 2026 | WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded ... |
| CVE-2026-33445 | MEDIUM | 5.9 | 0.3% | Jul 15, 2026 | CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate ... |
| CVE-2026-56743 | MEDIUM | 5.4 | 0.2% | Jul 15, 2026 | Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy s... |
| CVE-2026-49867 | MEDIUM | 6.3 | 0.3% | Jul 15, 2026 | DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template static resources le... |
| CVE-2026-45737 | MEDIUM | 6.5 | 0.3% | Jul 15, 2026 | Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Ar... |
| CVE-2026-40953 | MEDIUM | 4.4 | 0.1% | Jul 15, 2026 | CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers... |
| CVE-2026-33443 | MEDIUM | 5.9 | 0.2% | Jul 15, 2026 | CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledg... |
| CVE-2026-62947 | MEDIUM | 4.9 | 0.4% | Jul 15, 2026 | OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io aut... |
| CVE-2026-62355 | MEDIUM | 5.4 | — | Jul 15, 2026 | TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Rea... |
| CVE-2026-62353 | MEDIUM | 5.4 | — | Jul 15, 2026 | TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/p... |
| CVE-2026-62348 | MEDIUM | 5.4 | 0.2% | Jul 15, 2026 | TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, TDengine Enterprise allo... |
| CVE-2026-54443 | MEDIUM | 5.9 | — | Jul 15, 2026 | Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssF... |
| CVE-2026-49988 | MEDIUM | 6.8 | 0.2% | Jul 15, 2026 | Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, the Repomix MCP server attach_packed_... |
| CVE-2026-26032 | MEDIUM | 5.4 | — | Jul 15, 2026 | The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a... |
| CVE-2026-15746 | MEDIUM | 6.9 | — | Jul 15, 2026 | Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provide... |
| CVE-2026-61643 | MEDIUM | 5.9 | 0.2% | Jul 15, 2026 | FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, an authenticated FastGPT user can... |
| CVE-2026-56087 | MEDIUM | 6.1 | — | Jul 15, 2026 | Dell ThinOS 10, versions prior to 2605_10.2100 contain a Protection Mechanism Failure vulnerability. An attacker with ph... |
| CVE-2026-20298 | MEDIUM | 6.5 | 0.2% | Jul 15, 2026 | In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.26... |
| CVE-2026-14961 | MEDIUM | 6.2 | — | Jul 15, 2026 | Pegatron `Tdelo64.sys` exposes a privileged device interface, `\\.\TdeIo`, that fails to properly restrict access to sen... |
| CVE-2026-49997 | MEDIUM | 5.4 | 0.3% | Jul 15, 2026 | SurrealDB is a scalable, distributed, collaborative, document-graph database for the realtime web. Prior to 3.1.0, Docum... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now