2026 CVE Vulnerabilities

65,007 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-56128MEDIUM5.4pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Schedules: Edit privilege to ...
CVE-2026-56127MEDIUM5.4pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Rules: Edit privilege to inje...
CVE-2026-56126MEDIUM5.4pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Status: Monitoring privilege to inject ...
CVE-2026-35160MEDIUM5Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements use...
CVE-2026-84815MEDIUM5.8Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold allo...
CVE-2026-85173MEDIUM4.3n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that all...
CVE-2026-85172MEDIUM6.4n8n versions before 2.34.1 contain a server-side request forgery vulnerability in the legacy request helper function exp...
CVE-2026-85171MEDIUM6.5n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure vulnerability in the Strapi, SeaTable, and Mailch...
CVE-2026-85170MEDIUM6.5n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content in the Gmail (v1) and Brevo nodes to the mail comp...
CVE-2026-85167MEDIUM6.5n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection vulnerability in the Elasticsearch Document Get All...
CVE-2026-85166MEDIUM6.5n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate credential references in the inline workflow JSON of nodes ...
CVE-2026-85163MEDIUM6.5AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the EPG parser that allows authe...
CVE-2026-85162MEDIUM6.5AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in plugin/Live/saveLive.php that lac...
CVE-2026-85161MEDIUM4.3AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in removePoster.php that lacks forbi...
CVE-2026-85159MEDIUM5.4AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php where the cance...
CVE-2026-85158MEDIUM5.4AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in videoEmbeded.php that echoes ...
CVE-2026-85157MEDIUM5.3WWBN AVideo contains a broken access control vulnerability in the unauthenticated feed/index.php endpoint that disables ...
CVE-2026-85156MEDIUM5.3WWBN AVideo fails to properly validate access controls on the public channel page, allowing unauthenticated visitors to ...
CVE-2026-85107MEDIUM4.3A vulnerability was found in NousResearch hermes-agent 0.18.0. This vulnerability affects the function resourceBufferFro...
CVE-2026-85106MEDIUM6.3A vulnerability has been found in NousResearch hermes-agent 0.18.0. This affects the function fetchLinkTitle of the file...
CVE-2026-85100MEDIUM4.3A vulnerability was detected in 2FastLabs agent-squad up to 1.1.4. Affected by this vulnerability is the function AgentS...
CVE-2026-85093MEDIUM6.5Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when retriev...
CVE-2026-85092MEDIUM6.6LiME through 1.12.0 fails to validate the disk acquisition output path and does not use O_NOFOLLOW when opening the oper...
CVE-2026-85090MEDIUM5.4FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during A...
CVE-2026-85089MEDIUM6.5FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserv...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now