2026 CVE Vulnerabilities

44,992 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-20462MEDIUM6.7In Telephony, there is a possible memory corruption due to a heap buffer overflow. This could lead to local escalation o...
CVE-2026-20461MEDIUM5.3In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of ser...
CVE-2026-20460MEDIUM5.3In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote informa...
CVE-2026-20459MEDIUM5.3In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service...
CVE-2026-20457MEDIUM5.3In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service...
CVE-2026-57963MEDIUM6.5An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, an...
CVE-2026-57962MEDIUM5.3A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitr...
CVE-2026-54903MEDIUM6.3Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.load ...
CVE-2026-54902MEDIUM6.3Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to version 3.17.2, is vulnerabl...
CVE-2026-54901MEDIUM6.3Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj::Pars...
CVE-2026-54900MEDIUM6.3Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, when in ...
CVE-2026-54899MEDIUM6.3Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to version 3.17.2, disabling sy...
CVE-2026-54502MEDIUM6.3Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.dump ...
CVE-2026-54500MEDIUM5.3Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj.load ...
CVE-2026-56777MEDIUM5.3n8n before 2.25.7 and 2.26.x before 2.26.2 contains an abstract syntax tree (AST) security validator bypass in the Pytho...
CVE-2026-56399MEDIUM5.3Open WebUI before 0.6.27 contains a server-side request forgery vulnerability in the /api/v1/retrieval/process/web endpo...
CVE-2026-56377MEDIUM4.8ImageMagick before 7.1.2-24 contains an incorrect policy check that allows attackers to create or truncate files disallo...
CVE-2026-56369MEDIUM6.3ImageMagick before 7.1.2-22 contains an information disclosure vulnerability in the PasskeyEncipherImage method due to A...
CVE-2026-56365MEDIUM5.3ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers c...
CVE-2026-56363MEDIUM4.8ImageMagick before 7.1.2-22 contains a division by zero vulnerability in binomial kernel processing that allows attacker...
CVE-2026-56356MEDIUM5.4n8n contains a stored cross-site scripting vulnerability in the Chat Trigger node's Custom CSS field due to a misconfigu...
CVE-2026-56334MEDIUM5.3Capgo before 12.128.2 lacks an UPDATE row-level security policy for the build_requests table, preventing API-key and ano...
CVE-2026-56333MEDIUM5.3Capgo before 12.128.2 contains a server-side validation bypass vulnerability in organization security settings that allo...
CVE-2026-56331MEDIUM6.9Capgo before 12.128.2 contains improper error handling in the /private/accept_invitation endpoint that returns HTTP 500 ...
CVE-2026-56327MEDIUM6.9Capgo before 12.128.2 contains an information disclosure vulnerability in the public.invite_user_to_org RPC function tha...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now