2026 CVE Vulnerabilities

64,848 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-42229HIGH8.8n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the SeaTab...
CVE-2026-42228MEDIUM6.5n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket ...
CVE-2026-42227MEDIUM6.5n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated use...
CVE-2026-42226HIGH7.5n8n is an open source workflow automation platform. Prior to versions 1.123.33 and 2.17.5, the dynamic-node-parameters e...
CVE-2026-42154HIGH7.5Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote ...
CVE-2026-42151HIGH7.5Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_...
CVE-2026-41686MEDIUM4.4Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From...
CVE-2026-38751HIGH7.2OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionali...
CVE-2026-25863HIGH8.7Conditional Fields for Contact Form 7 WordPress plugin through version 2.7.2 contains an uncontrolled resource consumpti...
CVE-2026-43616HIGH7.8Detect-It-Easy prior to 3.21 contains a path traversal vulnerability that allows attackers to write arbitrary files to t...
CVE-2026-42796CRITICAL9.8Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoi...
CVE-2026-42146MEDIUM5.5CImg Library is a C++ library for image processing. Prior to commit c3aacf5, the nb_colors field read from the BMP file ...
CVE-2026-42144MEDIUM6.1CImg Library is a C++ library for image processing. Prior to commit 4ca26bc, there is an integer overflow vulnerability ...
CVE-2026-42140MEDIUM4.4PlantUML Macro is a macro for rendering UML diagrams from simple textual schemes. Prior to version 2.4.1, the PlantUML M...
CVE-2026-42138MEDIUM6.1Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, a...
CVE-2026-42092MEDIUM6.5titra is an open source time tracking project. In version 0.99.52, the globalsettings Meteor publication returns all glo...
CVE-2026-42091MEDIUM6.5goshs is a SimpleHTTPServer written in Go. Prior to version 2.0.2, the PUT upload handler (httpserver/updown.go) lacks t...
CVE-2026-42088HIGH8.1OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ...
CVE-2026-42087CRITICAL9.6OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ...
CVE-2026-42086MEDIUM4.6OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ...
CVE-2026-42085MEDIUM4.3OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ...
CVE-2026-42084HIGH8.1OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ...
CVE-2026-42052MEDIUM6Beets is the media library management system. Prior to version 2.10.0, the bundled web UI uses Underscore template inter...
CVE-2026-41572MEDIUM5.3Note Mark is an open-source note-taking application. Prior to version 0.19.3, after a note-mark owner soft-deletes a pub...
CVE-2026-41571CRITICAL9.4Note Mark is an open-source note-taking application. In version 0.19.2, IsPasswordMatch in backend/db/models.go falls ba...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now