2026 CVE Vulnerabilities
44,067 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59715 | MEDIUM | 6.5 | — | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.16 before 0.10.0, the Soc... |
| CVE-2026-59227 | MEDIUM | 5.4 | 0.3% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.11 before 0.10.0, POST /a... |
| CVE-2026-59226 | MEDIUM | 4.3 | — | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0, execute_... |
| CVE-2026-59225 | MEDIUM | 6.3 | — | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.12 before 0.10.0, an auth... |
| CVE-2026-59223 | MEDIUM | 4.3 | 0.2% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, WEB_FETCH_FILTER_... |
| CVE-2026-59222 | MEDIUM | 6.5 | 0.3% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 before 0.10.0, GET /api... |
| CVE-2026-59220 | MEDIUM | 6.5 | 0.3% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.2 before 0.10.0, the SKIL... |
| CVE-2026-59218 | MEDIUM | 5.3 | 0.2% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the /api/v1/auths... |
| CVE-2026-59217 | MEDIUM | 4.3 | 0.3% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the file upload p... |
| CVE-2026-59213 | MEDIUM | 5 | 0.3% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 before 0.10.0, get_all... |
| CVE-2026-59212 | MEDIUM | 5.4 | 0.3% | Jul 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _verify_... |
| CVE-2026-59209 | MEDIUM | 6.5 | 0.3% | Jul 9, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with... |
| CVE-2026-51598 | MEDIUM | 6.5 | 0.2% | Jul 9, 2026 | An input validation vulnerability in the RTSP service of MERCURY MIPC252W IP Camera v1.0.5 Build 230306 Rel.79931n) allo... |
| CVE-2026-15193 | MEDIUM | 5.3 | — | Jul 9, 2026 | A vulnerability was determined in AidanPark openclaw-android up to 0.4.0. The affected element is an unknown function of... |
| CVE-2026-15192 | MEDIUM | 6.5 | — | Jul 9, 2026 | A vulnerability has been found in mettle sendportal up to 3.0.1. This issue affects the function sendgrid/postmark/posta... |
| CVE-2026-15191 | MEDIUM | 6.3 | 0.2% | Jul 9, 2026 | A flaw has been found in mettle sendportal up to 3.0.1. This vulnerability affects unknown code of the file vendor/mettl... |
| CVE-2026-61474 | MEDIUM | 5.3 | — | Jul 9, 2026 | An improper authorization check in MISP’s attribute creation endpoint allowed an authenticated user with permission to a... |
| CVE-2026-59208 | MEDIUM | 6.8 | 0.1% | Jul 9, 2026 | n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances confi... |
| CVE-2026-59207 | MEDIUM | 6.5 | — | Jul 9, 2026 | n8n is an open source workflow automation platform. Prior to 2.27.4 and 2.28.1, the AI Agents feature did not enforce th... |
| CVE-2026-15189 | MEDIUM | 6.3 | — | Jul 9, 2026 | A security vulnerability has been detected in aerostackdev aerostack-mcp up to 6315dfde7df0a15aaf743f88d91347115e09ba23.... |
| CVE-2026-15188 | MEDIUM | 6.3 | — | Jul 9, 2026 | A weakness has been identified in manjurulhoque django-job-portal up to dfa352f305bba44445ac5dc12e9b2a98c9dcd71f. Affect... |
| CVE-2026-15187 | MEDIUM | 4.3 | — | Jul 9, 2026 | A security flaw has been discovered in enquirer up to 2.4.1. Affected is the function Enquirer.set of the component Publ... |
| CVE-2026-5005 | MEDIUM | 5.4 | — | Jul 9, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Twiser Informatics... |
| CVE-2026-54800 | MEDIUM | 6.3 | — | Jul 9, 2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base syst... |
| CVE-2026-60095 | MEDIUM | 6.9 | 0.5% | Jul 9, 2026 | Vinchin Backup & Recovery through 9.0.0.86562 contains a stack buffer overflow vulnerability in the ModuleHandShake func... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now