2026 CVE Vulnerabilities
64,848 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42229 | HIGH | 8.8 | 0.3% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the SeaTab... |
| CVE-2026-42228 | MEDIUM | 6.5 | 0.4% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket ... |
| CVE-2026-42227 | MEDIUM | 6.5 | 0.2% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated use... |
| CVE-2026-42226 | HIGH | 7.5 | 0.3% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.33 and 2.17.5, the dynamic-node-parameters e... |
| CVE-2026-42154 | HIGH | 7.5 | 0.8% | May 4, 2026 | Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote ... |
| CVE-2026-42151 | HIGH | 7.5 | 0.4% | May 4, 2026 | Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_... |
| CVE-2026-41686 | MEDIUM | 4.4 | 0.1% | May 4, 2026 | Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From... |
| CVE-2026-38751 | HIGH | 7.2 | 0.4% | May 4, 2026 | OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionali... |
| CVE-2026-25863 | HIGH | 8.7 | 0.4% | May 4, 2026 | Conditional Fields for Contact Form 7 WordPress plugin through version 2.7.2 contains an uncontrolled resource consumpti... |
| CVE-2026-43616 | HIGH | 7.8 | 0.2% | May 4, 2026 | Detect-It-Easy prior to 3.21 contains a path traversal vulnerability that allows attackers to write arbitrary files to t... |
| CVE-2026-42796 | CRITICAL | 9.8 | 0.7% | May 4, 2026 | Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoi... |
| CVE-2026-42146 | MEDIUM | 5.5 | 0.1% | May 4, 2026 | CImg Library is a C++ library for image processing. Prior to commit c3aacf5, the nb_colors field read from the BMP file ... |
| CVE-2026-42144 | MEDIUM | 6.1 | 0.1% | May 4, 2026 | CImg Library is a C++ library for image processing. Prior to commit 4ca26bc, there is an integer overflow vulnerability ... |
| CVE-2026-42140 | MEDIUM | 4.4 | 0.2% | May 4, 2026 | PlantUML Macro is a macro for rendering UML diagrams from simple textual schemes. Prior to version 2.4.1, the PlantUML M... |
| CVE-2026-42138 | MEDIUM | 6.1 | 0.2% | May 4, 2026 | Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, a... |
| CVE-2026-42092 | MEDIUM | 6.5 | 0.2% | May 4, 2026 | titra is an open source time tracking project. In version 0.99.52, the globalsettings Meteor publication returns all glo... |
| CVE-2026-42091 | MEDIUM | 6.5 | 0.2% | May 4, 2026 | goshs is a SimpleHTTPServer written in Go. Prior to version 2.0.2, the PUT upload handler (httpserver/updown.go) lacks t... |
| CVE-2026-42088 | HIGH | 8.1 | 0.3% | May 4, 2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2026-42087 | CRITICAL | 9.6 | 0.3% | May 4, 2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2026-42086 | MEDIUM | 4.6 | 0.2% | May 4, 2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2026-42085 | MEDIUM | 4.3 | 0.3% | May 4, 2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2026-42084 | HIGH | 8.1 | 0.3% | May 4, 2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2026-42052 | MEDIUM | 6 | 0.3% | May 4, 2026 | Beets is the media library management system. Prior to version 2.10.0, the bundled web UI uses Underscore template inter... |
| CVE-2026-41572 | MEDIUM | 5.3 | 0.2% | May 4, 2026 | Note Mark is an open-source note-taking application. Prior to version 0.19.3, after a note-mark owner soft-deletes a pub... |
| CVE-2026-41571 | CRITICAL | 9.4 | 0.3% | May 4, 2026 | Note Mark is an open-source note-taking application. In version 0.19.2, IsPasswordMatch in backend/db/models.go falls ba... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now