2026 CVE Vulnerabilities

67,200 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-33219MEDIUM5.3NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.1...
CVE-2026-33218HIGH7.5NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.1...
CVE-2026-33217MEDIUM6.5NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.1...
CVE-2026-33216HIGH7.5NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.1...
CVE-2026-29785HIGH7.5NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.1...
CVE-2026-27889HIGH7.5NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2....
CVE-2026-33809MEDIUM5.3A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excess...
CVE-2026-33751MEDIUM4.8n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, a flaw in the LDAP n...
CVE-2026-33749CRITICAL9n8n is an open source workflow automation platform. Prior to versions 1.123.27, 2.13.3, and 2.14.1, an authenticated use...
CVE-2026-33724HIGH7.4n8n is an open source workflow automation platform. Prior to version 2.5.0, when the Source Control feature is configure...
CVE-2026-33722MEDIUM5.3n8n is an open source workflow automation platform. Prior to versions 2.6.4 and 1.123.23, an authenticated user without ...
CVE-2026-33720MEDIUM4.2n8n is an open source workflow automation platform. Prior to version 2.8.0, when the `N8N_SKIP_AUTH_ON_OAUTH_CALLBACK` e...
CVE-2026-27602HIGH7.2Modoboa is a mail hosting and management platform. Prior to version 2.7.1, `exec_cmd()` in `modoboa/lib/sysutils.py` alw...
CVE-2026-1001MEDIUM4.8Domoticz versions prior to 2026.1 contain a stored cross-site scripting vulnerability in the Add Hardware and rename dev...
CVE-2026-33713HIGH8.8n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated use...
CVE-2026-33696HIGH8.8n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated use...
CVE-2026-33665HIGH7.5n8n is an open source workflow automation platform. Prior to versions 2.4.0 and 1.121.0, when LDAP authentication is ena...
CVE-2026-33663MEDIUM6.5n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated use...
CVE-2026-33660HIGH8.8n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated use...
CVE-2026-30587HIGH8.7Multiple Stored XSS vulnerabilities exist in Seafile Server version 13.0.15,13.0.16-pro,12.0.14 and prior and fixed in 1...
CVE-2026-27496MEDIUM6.5n8n is an open source workflow automation platform. Prior to versions 1.123.22, 2.9.3, and 2.10.1, an authenticated user...
CVE-2026-3988HIGH7.5GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 1...
CVE-2026-3857HIGH8.8GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.8.7, 18.9 before 18.9.3, and ...
CVE-2026-34085HIGH7.8fontconfig before 2.17.1 has an off-by-one error in allocation during sfnt capability handling, leading to a one-byte ou...
CVE-2026-32573CRITICAL9.1Improper Control of Generation of Code ('Code Injection') vulnerability in Nelio Software Nelio AB Testing nelio-ab-test...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now