2026 CVE Vulnerabilities

43,225 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-6727MEDIUM5.9A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with a...
CVE-2026-56720MEDIUM5.3CamaleonCMS version 2.9.2 and earlier contains a missing authorization vulnerability in the admin users controller that ...
CVE-2026-53414MEDIUM6.5Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting partic...
CVE-2026-19078MEDIUM4.3A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the...
CVE-2026-18638MEDIUM6.5Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server proces...
CVE-2026-14180MEDIUM5.3A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to han...
CVE-2026-11814MEDIUM4.9A command injection vulnerability in the listed NETGEAR models allows a network-adjacent attacker with the ability to in...
CVE-2026-11739MEDIUM4.9A command injection vulnerability in certain affected NETGEAR Nighthawk devices allows a network-adjacent attacker with...
CVE-2026-11738MEDIUM4.3Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected t...
CVE-2026-11737MEDIUM4.3Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected ...
CVE-2026-73067MEDIUM6.7Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata model loaded through TessBaseAPI::Init ca...
CVE-2026-73066MEDIUM6.8Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata LSTM model component loaded through Tesse...
CVE-2026-72925MEDIUM6.1SWC is a TypeScript / JavaScript compiler written in Rust. Prior to @swc/html 1.15.47-nightly-20260729.1 and swc_html_mi...
CVE-2026-18636MEDIUM6.8The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users fr...
CVE-2026-17535MEDIUM6.2Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by...
CVE-2026-73210MEDIUM5.1A Server-Side Request Forgery (SSRF) vulnerability existed in Lookyloo's PlaywrightCapture when the only_global_lookup o...
CVE-2026-19434MEDIUM5.1Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute ar...
CVE-2026-72784MEDIUM6.9Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulne...
CVE-2026-72783MEDIUM6.2Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakne...
CVE-2026-72775MEDIUM5.8n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which interp...
CVE-2026-72773MEDIUM4.9n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in the @n8n/computer-use file-search (searc...
CVE-2026-72769MEDIUM6.1n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An aut...
CVE-2026-72768MEDIUM6.4n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node ...
CVE-2026-72764MEDIUM5.8n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected versions (...
CVE-2026-72750MEDIUM5.3n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query ope...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now