2026 CVE Vulnerabilities

45,455 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-25945CRITICAL9.8The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen...
CVE-2026-25851CRITICAL9.8WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona...
CVE-2026-25114CRITICAL9.8The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen...
CVE-2026-25113CRITICAL9.8The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen...
CVE-2026-24731CRITICAL9.8WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona...
CVE-2026-20792CRITICAL9.8The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absen...
CVE-2026-20781CRITICAL9.8WebSocket endpoints lack proper authentication mechanisms, enabling attackers to perform unauthorized station impersona...
CVE-2026-28215CRITICAL9.1hoppscotch is an open source API development ecosystem. Prior to version 2026.2.0, an unauthenticated attacker can overw...
CVE-2026-28213CRITICAL9.8EverShop is a TypeScript-first eCommerce platform. Versions prior to 2.1.1 have a vulnerability in the "Forgot Password"...
CVE-2026-3261CRITICAL9.8A flaw has been found in itsourcecode School Management System 1.0. This impacts an unknown function of the file /settin...
CVE-2026-22207CRITICAL9.8OpenViking through version 0.1.18, prior to commit 0251c70, contains a broken access control vulnerability that allows u...
CVE-2026-27975CRITICAL9.8Ajenti is a Linux and BSD modular server admin panel. Prior to version 2.2.13, an unauthenticated user could gain access...
CVE-2026-27966CRITICAL9.8Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to version 1.8.0, the CSV Agent nod...
CVE-2026-27965CRITICAL9.9Vitess is a database clustering system for horizontal scaling of MySQL. Prior to versions 23.0.3 and 22.0.4, anyone with...
CVE-2026-27952CRITICAL9.9Agenta is an open-source LLMOps platform. In Agenta-API prior to version 0.48.1, a Python sandbox escape vulnerability e...
CVE-2026-27941CRITICAL9.9OpenLIT is an open source platform for AI engineering. Prior to version 1.37.1, several GitHub Actions workflows in Open...
CVE-2026-27837CRITICAL9.8Dottie provides nested object access and manipulation in JavaScript. Versions 2.0.4 through 2.0.6 contain an incomplete ...
CVE-2026-27812CRITICAL9.1Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. A vuln...
CVE-2026-27809CRITICAL9.1psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.12.2, when a PSD file conta...
CVE-2026-27804CRITICAL9.1Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version...
CVE-2026-27613CRITICAL9.8TinyWeb is a web server (HTTP, HTTPS) written in Delphi for Win32. A vulnerability in versions prior to 2.01 allows unau...
CVE-2026-27577CRITICAL9.9n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits i...
CVE-2026-27495CRITICAL9.9n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user...
CVE-2026-27494CRITICAL9.9n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user...
CVE-2026-27493CRITICAL9n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, a second-order expres...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now