2026 CVE Vulnerabilities

44,088 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-60124MEDIUM5.3An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys wit...
CVE-2026-60092MEDIUM6.1AVideo (Meet plugin) through commit e8d6119f3cb1b849149906efeb0a41fc024f59f8 contains a stored cross-site scripting vuln...
CVE-2026-59253MEDIUM5n8n before 2.28.0 contains an improper authorization vulnerability allowing authenticated users to assign workflows to f...
CVE-2026-58657MEDIUM4.8Grav before 2.0.0 (affected through 2.0.0-rc.9 and the 2.0 branch) contains a stored CSS injection vulnerability in the ...
CVE-2026-58654MEDIUM5.3The Grav API plugin (getgrav/grav-plugin-api) 1.0.0 contains an unrestricted file upload vulnerability in the avatar upl...
CVE-2026-56778MEDIUM6.4n8n before 2.25.7 and 2.26.x before 2.26.2 contains an authorization bypass in the Public API execution retry endpoint, ...
CVE-2026-56775MEDIUM5.4n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization vulnerability in three mutating evaluation test-run en...
CVE-2026-56362MEDIUM4.2ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache...
CVE-2026-56360MEDIUM6.3n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger ...
CVE-2026-56359MEDIUM5.4n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management flow where authenticated use...
CVE-2026-56298MEDIUM5.3Capgo before 12.128.2 fails to strip EXIF metadata from images uploaded via the app information endpoint, exposing sensi...
CVE-2026-56293MEDIUM5.4Capgo before 12.128.2 contains an authorization flaw in transfer_app() that fails to update deploy_history.owner_org whe...
CVE-2026-56284MEDIUM6.9Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST RPC func...
CVE-2026-56283MEDIUM5.4Capgo before 12.128.2 contains an html injection vulnerability in the organization settings endpoint that allows attacke...
CVE-2026-56273MEDIUM6.5Flowise before 3.1.0 contains a path traversal vulnerability in Faiss and SimpleStore vector store implementations that ...
CVE-2026-56217MEDIUM5.3Capgo before 12.128.2 contains a policy bypass vulnerability in app_versions update enforcement that allows app-scoped A...
CVE-2026-15034MEDIUM4.3A vulnerability has been found in flask-dashboard Flask-MonitoringDashboard up to 5.0.2. Affected by this issue is some ...
CVE-2026-15033MEDIUM6.3A flaw has been found in christopherthielen check-peer-dependencies up to 4.3.4. Affected by this vulnerability is the f...
CVE-2026-8315MEDIUM5.4Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Desig...
CVE-2026-8310MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Desig...
CVE-2026-6740MEDIUM6.4The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Stored Cro...
CVE-2026-6459MEDIUM6.4The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored ...
CVE-2026-5459MEDIUM5.3The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP...
CVE-2026-12002MEDIUM4.7The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request ...
CVE-2026-6742MEDIUM6.4The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in ...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now