2026 CVE Vulnerabilities

43,808 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-55608MEDIUM5.4n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior...
CVE-2026-55410MEDIUM6.7NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t...
CVE-2026-55399MEDIUM4.3CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with vali...
CVE-2026-52888MEDIUM6.8NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0....
CVE-2026-38753MEDIUM4.9A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Serv...
CVE-2026-33684MEDIUM5.3WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded ...
CVE-2026-33445MEDIUM5.9CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate ...
CVE-2026-56743MEDIUM5.4Cilium is a networking, observability, and security solution. From 1.19.0 to 1.19.4, standard Kubernetes NetworkPolicy s...
CVE-2026-49867MEDIUM6.3DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase template static resources le...
CVE-2026-45737MEDIUM6.5Argo CD is a declarative, GitOps continuous delivery tool for Kubernetes. From 3.2.0 until 3.2.12, 3.3.10, and 3.4.2, Ar...
CVE-2026-40953MEDIUM4.4CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers...
CVE-2026-33443MEDIUM5.9CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledg...
CVE-2026-62947MEDIUM4.9OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, the cgi-download handler in cgi-io aut...
CVE-2026-62355MEDIUM5.4TDengine is an open source, time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, a Data Rea...
CVE-2026-62353MEDIUM5.4TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.14, source/libs/parser/src/p...
CVE-2026-62348MEDIUM5.4TDengine is a time-series database optimized for Internet of Things devices. Prior to 3.4.1.15, TDengine Enterprise allo...
CVE-2026-54443MEDIUM5.9Dashy is a self-hostable personal dashboard. From 1.9.4 until 3.2.0, the Dashy RSS Widget in src/components/Widgets/RssF...
CVE-2026-49988MEDIUM6.8Repomix is a tool that packs repositories into AI-friendly files. Prior to 1.14.1, the Repomix MCP server attach_packed_...
CVE-2026-26032MEDIUM5.4The PackagerResolver of Apache Ivy is able to download online artifacts and to (re)package them in a format defined by a...
CVE-2026-15746MEDIUM6.9Strands Agents is an open-source Python SDK for building and running AI agents. The strands-agents-tools package provide...
CVE-2026-61643MEDIUM5.9FastGPT is a knowledge-based AI application platform. From 4.14.17 until 4.15.0-beta5, an authenticated FastGPT user can...
CVE-2026-56087MEDIUM6.1Dell ThinOS 10, versions prior to 2605_10.2100 contain a Protection Mechanism Failure vulnerability. An attacker with ph...
CVE-2026-20298MEDIUM6.5In Splunk Enterprise versions below 10.4.1, 10.2.5, 10.0.8, and 9.4.13, and Splunk Cloud Platform versions below 10.5.26...
CVE-2026-14961MEDIUM6.2Pegatron `Tdelo64.sys` exposes a privileged device interface, `\\.\TdeIo`, that fails to properly restrict access to sen...
CVE-2026-49997MEDIUM5.4SurrealDB is a scalable, distributed, collaborative, document-graph database for the realtime web. Prior to 3.1.0, Docum...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now