2026 CVE Vulnerabilities

64,997 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-19301MEDIUM6.5IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to...
CVE-2026-19299MEDIUM6.5IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to...
CVE-2026-18887MEDIUM6.5IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker ...
CVE-2026-18858MEDIUM5.5IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SS...
CVE-2026-18567MEDIUM4.7IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a race condition involv...
CVE-2026-9186MEDIUM6.5IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration i...
CVE-2026-9138MEDIUM6.5IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the ser...
CVE-2026-8447MEDIUM6.1IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site scripting vulnerability in the Playground chat int...
CVE-2026-85700MEDIUM6.5Onyx 4.6.6 fails to properly restrict access to custom tool credentials stored in custom_headers, allowing any authentic...
CVE-2026-85698MEDIUM5.5Turso through 0.8.0-pre.8 contains an out-of-bounds read vulnerability in the table-leaf page reader that uses an attack...
CVE-2026-85697MEDIUM6.5Documenso 2.17.0 contains an access control vulnerability in the PDF-serving endpoint that fails to validate document vi...
CVE-2026-85693MEDIUM6.5Chatbot UI contains an authorization bypass vulnerability in the retrieval endpoint that allows authenticated attackers ...
CVE-2026-85692MEDIUM6.5Nightingale (n9e), as of commit 8362cbe (main branch, confirmed 2026-08-27), contains a server-side request forgery vuln...
CVE-2026-85689MEDIUM6.5llmware 0.4.6 contains an SQL injection vulnerability in the collection-database layer (llmware/resources.py) where filt...
CVE-2026-85676MEDIUM4.3Dub contains an open redirect vulnerability in the redir_url query parameter that is accepted on every short link withou...
CVE-2026-85670MEDIUM6.5tokenizers (Hugging Face) is affected by an out-of-bounds buffer access in BpeBuilder::build (tokenizers/src/models/bpe/...
CVE-2026-85669MEDIUM6.5potpie through 2.0.0 fails to verify user ownership on the POST /conversations/{conversation_id}/code-changes/sync endpo...
CVE-2026-85665MEDIUM6.5Bruno versions through 4.1.0 fail to validate file paths in request body declarations, allowing attackers to read arbitr...
CVE-2026-85662MEDIUM5.3Marqo 2.26.0 contains a server-side request forgery vulnerability in the add_documents endpoint that allows unauthentica...
CVE-2026-85650MEDIUM5.4Trigger.dev before 4.5.2 contains a server-side request forgery vulnerability in webhook alert channel delivery URLs tha...
CVE-2026-85624MEDIUM6.5Blinko 1.8.7 contains a cross-user private note disclosure vulnerability in the noteReferenceList procedure that perform...
CVE-2026-85622MEDIUM5.3AppFlowy-Cloud through 0.9.64 fails to validate workspace membership when establishing WebSocket connections in the esta...
CVE-2026-85621MEDIUM6.5LobeChat (LobeHub) 2.2.1 does not properly verify inbound chat-platform webhook signatures in the QQ and Feishu adapters...
CVE-2026-85618MEDIUM6.5ConvertX 0.17.0 contains an arbitrary file read vulnerability in the xelatex converter that allows authenticated users t...
CVE-2026-85605MEDIUM5.3Slink before 1.12.3 fails to properly authorize access to image comment endpoints, allowing unauthenticated attackers to...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now