2026 CVE Vulnerabilities

43,858 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-56375MEDIUM4.8ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action fails. Attackers ca...
CVE-2026-56353MEDIUM6.3n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configu...
CVE-2026-56352MEDIUM6.4n8n before 2.19.3 contains a file path restriction bypass in the legacy ExecuteWorkflow node's localFile source option, ...
CVE-2026-56349MEDIUM6.3n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allows attackers to bypa...
CVE-2026-40633MEDIUM5.5Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sen...
CVE-2026-49501MEDIUM6.7Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Pri...
CVE-2026-11580MEDIUM5.5The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capab...
CVE-2026-11579MEDIUM5.3The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload ...
CVE-2026-15030MEDIUM5.6Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows ...
CVE-2026-11851MEDIUM5.9Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of ...
CVE-2026-9770MEDIUM5.3Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is s...
CVE-2026-13230MEDIUM6.5An information disclosure vulnerability was identified in TP-Link Kasa EC70 v4 and EC71 v4 in the local discovery mechan...
CVE-2026-36035MEDIUM6.5Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Ser...
CVE-2026-15753MEDIUM5.4A vulnerability was determined in zhinianboke xianyu-auto-reply on Server. Affected by this vulnerability is an unknown ...
CVE-2026-15751MEDIUM5.3A security vulnerability has been detected in mastergo-design mastergo-magic-mcp up to 0.2.0. The affected element is th...
CVE-2026-59732MEDIUM5Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1...
CVE-2026-48357MEDIUM6.2CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application...
CVE-2026-48354MEDIUM6.2CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati...
CVE-2026-48353MEDIUM5.5CAI Content Credentials is affected by an Improper Input Validation vulnerability that could lead to arbitrary file syst...
CVE-2026-48312MEDIUM6.8CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur...
CVE-2026-48302MEDIUM6.2CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in an application de...
CVE-2026-48298MEDIUM6.2CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a...
CVE-2026-48296MEDIUM6.2CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an a...
CVE-2026-47732MEDIUM6.5Twig is a template language for PHP. Prior to 3.26.0, several Twig language constructs trigger PHP string coercion on a ...
CVE-2026-47730MEDIUM5.4Twig is a template language for PHP. From 3.0.0 until 3.26.0, Twig\Profiler\Dumper\HtmlDumper writes Profile::getTemplat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now