2026 CVE Vulnerabilities
44,088 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-60124 | MEDIUM | 5.3 | 0.2% | Jul 8, 2026 | An authorization bypass in MISP’s EventsController::importModule() allowed authenticated users or read-only API keys wit... |
| CVE-2026-60092 | MEDIUM | 6.1 | 0.2% | Jul 8, 2026 | AVideo (Meet plugin) through commit e8d6119f3cb1b849149906efeb0a41fc024f59f8 contains a stored cross-site scripting vuln... |
| CVE-2026-59253 | MEDIUM | 5 | — | Jul 8, 2026 | n8n before 2.28.0 contains an improper authorization vulnerability allowing authenticated users to assign workflows to f... |
| CVE-2026-58657 | MEDIUM | 4.8 | — | Jul 8, 2026 | Grav before 2.0.0 (affected through 2.0.0-rc.9 and the 2.0 branch) contains a stored CSS injection vulnerability in the ... |
| CVE-2026-58654 | MEDIUM | 5.3 | — | Jul 8, 2026 | The Grav API plugin (getgrav/grav-plugin-api) 1.0.0 contains an unrestricted file upload vulnerability in the avatar upl... |
| CVE-2026-56778 | MEDIUM | 6.4 | — | Jul 8, 2026 | n8n before 2.25.7 and 2.26.x before 2.26.2 contains an authorization bypass in the Public API execution retry endpoint, ... |
| CVE-2026-56775 | MEDIUM | 5.4 | — | Jul 8, 2026 | n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization vulnerability in three mutating evaluation test-run en... |
| CVE-2026-56362 | MEDIUM | 4.2 | 0.2% | Jul 8, 2026 | ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache... |
| CVE-2026-56360 | MEDIUM | 6.3 | — | Jul 8, 2026 | n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger ... |
| CVE-2026-56359 | MEDIUM | 5.4 | 0.1% | Jul 8, 2026 | n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management flow where authenticated use... |
| CVE-2026-56298 | MEDIUM | 5.3 | — | Jul 8, 2026 | Capgo before 12.128.2 fails to strip EXIF metadata from images uploaded via the app information endpoint, exposing sensi... |
| CVE-2026-56293 | MEDIUM | 5.4 | — | Jul 8, 2026 | Capgo before 12.128.2 contains an authorization flaw in transfer_app() that fails to update deploy_history.owner_org whe... |
| CVE-2026-56284 | MEDIUM | 6.9 | — | Jul 8, 2026 | Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST RPC func... |
| CVE-2026-56283 | MEDIUM | 5.4 | — | Jul 8, 2026 | Capgo before 12.128.2 contains an html injection vulnerability in the organization settings endpoint that allows attacke... |
| CVE-2026-56273 | MEDIUM | 6.5 | 0.3% | Jul 8, 2026 | Flowise before 3.1.0 contains a path traversal vulnerability in Faiss and SimpleStore vector store implementations that ... |
| CVE-2026-56217 | MEDIUM | 5.3 | — | Jul 8, 2026 | Capgo before 12.128.2 contains a policy bypass vulnerability in app_versions update enforcement that allows app-scoped A... |
| CVE-2026-15034 | MEDIUM | 4.3 | — | Jul 8, 2026 | A vulnerability has been found in flask-dashboard Flask-MonitoringDashboard up to 5.0.2. Affected by this issue is some ... |
| CVE-2026-15033 | MEDIUM | 6.3 | — | Jul 8, 2026 | A flaw has been found in christopherthielen check-peer-dependencies up to 4.3.4. Affected by this vulnerability is the f... |
| CVE-2026-8315 | MEDIUM | 5.4 | — | Jul 8, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Desig... |
| CVE-2026-8310 | MEDIUM | 6.1 | — | Jul 8, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Desig... |
| CVE-2026-6740 | MEDIUM | 6.4 | — | Jul 8, 2026 | The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Stored Cro... |
| CVE-2026-6459 | MEDIUM | 6.4 | — | Jul 8, 2026 | The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored ... |
| CVE-2026-5459 | MEDIUM | 5.3 | — | Jul 8, 2026 | The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordP... |
| CVE-2026-12002 | MEDIUM | 4.7 | — | Jul 8, 2026 | The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Cross-Site Request ... |
| CVE-2026-6742 | MEDIUM | 6.4 | — | Jul 8, 2026 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'additional' parameter in ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now