2026 CVE Vulnerabilities

64,785 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41486HIGH8.8Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension typ...
CVE-2026-44400CRITICAL9.8MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile ...
CVE-2026-7807HIGH8.8SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary...
CVE-2026-44694CRITICAL9.1n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. From ...
CVE-2026-42282MEDIUM4.3n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior...
CVE-2026-42190MEDIUM5.3RedwoodSDK is a server-first React framework. From version 1.0.0-beta.50 to before version 1.2.3, server actions in rwsd...
CVE-2026-42189HIGH7.5Russh is a Rust SSH client & server library. Prior to version 0.60.1, a pre-authentication denial-of-service vulnerabili...
CVE-2026-42185MEDIUM5.5People is an application to handle users and teams, and distribute permissions across La Suite. Prior to version 1.25.0,...
CVE-2026-42181MEDIUM6.5Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy fetches metadata for user-suppli...
CVE-2026-42180MEDIUM6.3Lemmy is a link aggregator and forum for the fediverse. Prior to version 0.19.18, Lemmy allows an authenticated low-priv...
CVE-2026-42176MEDIUM6.7Scoold is a Q&A and a knowledge sharing platform for teams. Prior to version 1.67.0, Scoold allows the admins configurat...
CVE-2026-42160CRITICAL10Data Space Portal is an open-source Software as a Service (SaaS) solution designed to streamline Dataspace management. F...
CVE-2026-41495MEDIUM5.3n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior...
CVE-2026-8178CRITICAL9.2An issue exists in Amazon Redshift JDBC Driver versions prior to 2.2.2. Under certain conditions, the driver could load ...
CVE-2026-41511MEDIUM5.5OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Sto...
CVE-2026-29203HIGH8.8A chmod call in the cPanel Nova plugin's Cpanel::Nova::Connector follows symlinks, allowing setting root permissions on ...
CVE-2026-29202HIGH8.8Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution...
CVE-2026-29201HIGH8.6Insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause arbitrary f...
CVE-2026-6659HIGH7.5Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function ...
CVE-2026-42072CRITICAL9.8Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and wri...
CVE-2026-42030MEDIUM6.1MapServer is a system for developing web-based GIS applications. From version 6.0 to before version 8.6.2, a reflected X...
CVE-2026-42028MEDIUM5.3novaGallery is a php image gallery. Prior to version 2.1.1, a path traversal vulnerability has been identified in novaGa...
CVE-2026-41889CRITICAL9.8pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simp...
CVE-2026-41887MEDIUM4.9Flarum is open-source forum software. Prior to versions 1.8.16 and 2.0.0-rc.1, Flarum's patch for CVE-2023-27577 restric...
CVE-2026-38360CRITICAL9.8Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execut...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now