2026 CVE Vulnerabilities

64,952 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-41267CRITICAL9.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mas...
CVE-2026-41266HIGH7.5Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-...
CVE-2026-41265CRITICAL9.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific fl...
CVE-2026-41264CRITICAL9.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific fl...
CVE-2026-41138HIGH8.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, there is a remo...
CVE-2026-41137HIGH8.8Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, The CSVAgent al...
CVE-2026-25874CRITICAL9.8LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.load...
CVE-2026-6074CRITICAL9.8Intrado 911 Emergency Gateway (EGW) 5.x, 6.x, and 7.x contain a path traversal vulnerability in the download_debuglog_fi...
CVE-2026-41259HIGH7.5Mastodon is a free, open-source social network server based on ActivityPub. Prior to v4.5.9, v4.4.16, and v4.3.22, Masto...
CVE-2026-41247CRITICAL9.8elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contai...
CVE-2026-41246HIGH8.1Contour is a Kubernetes ingress controller using Envoy proxy. From v1.19.0 to before v1.33.4, v1.32.5, and v1.31.6, Cont...
CVE-2026-41241MEDIUM5.4pretalx is a conference planning tool. Prior to 2026.1.0, The organiser search in the pretalx backend rendered submissio...
CVE-2026-41213MEDIUM5.9@node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchange path accepts RFC7...
CVE-2026-41205HIGH7.5Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path trave...
CVE-2026-41173MEDIUM5.9The AWS X-Ray Remote Sampler package provides a sampler which can get sampling configurations from AWS X-Ray. Prior to 0...
CVE-2026-41078MEDIUM5.9OpenTelemetry dotnet is a dotnet telemetry framework. In 1.6.0-rc.1 and earlier, OpenTelemetry.Exporter.Jaeger may allow...
CVE-2026-40894MEDIUM5.3OpenTelemetry dotnet is a dotnet telemetry framework. In OpenTelemetry.Api 0.5.0-beta.2 to 1.15.2 and OpenTelemetry.Exte...
CVE-2026-40886HIGH7.7Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3....
CVE-2026-33694HIGH7.8This vulnerability allows an attacker to create a junction, enabling the deletion of arbitrary files with SYSTEM privile...
CVE-2026-31173MEDIUM6.5An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...
CVE-2026-31169MEDIUM6.5An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...
CVE-2026-31168MEDIUM6.5An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...
CVE-2026-31167MEDIUM6.5An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...
CVE-2026-31166MEDIUM6.5An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...
CVE-2026-31163MEDIUM6.5An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary comm...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now