2026 CVE Vulnerabilities

45,449 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-59257HIGH8.8n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the legacy My...
CVE-2026-58656HIGH8.7Grav API plugin before v1.0.0-rc.16 accepts JWT tokens via the ?token= URL query parameter and responds with Access-Cont...
CVE-2026-56776HIGH7.4n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypass in the POST /workflows/{workflowId}/test-runs/n...
CVE-2026-56374HIGH7.1ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary ch...
CVE-2026-56297HIGH8.1FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcman_channel_close and dvcman_call_on_receive due to ...
CVE-2026-56250HIGH8.7Capgo before 12.128.2 allows upload-scoped API keys to modify the mutable app_versions.r2_path field through PostgREST, ...
CVE-2026-56246HIGH8.1Capgo before 12.128.2 contains a broken access control vulnerability in the organization management API where a scoped A...
CVE-2026-56226HIGH8.7Capgo (Cap-go/capgo) before 12.128.2 exposes the Supabase PostgREST RPC function public.get_orgs_v6(userid uuid), which ...
CVE-2026-56220HIGH7.1Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.manifest INSERT policy that allows re...
CVE-2026-56086HIGH8.8Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-53482HIGH7.5Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-44840HIGH7.5Dgraph is an open source distributed GraphQL database. Prior to version 25.3.4, the `checkUserPassword` GraphQL query in...
CVE-2026-41122HIGH7.1Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-22927HIGH7.8Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.
CVE-2026-15053HIGH7.5Tanium addressed a denial of service vulnerability in Tanium Server.
CVE-2026-15035HIGH7.8A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm...
CVE-2026-6820HIGH7.2The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ema...
CVE-2026-5356HIGH7.5The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Input...
CVE-2026-6854HIGH7.5The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the ...
CVE-2026-6818HIGH7.2The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'spe...
CVE-2026-6230HIGH7.5The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all ve...
CVE-2026-3688HIGH8.1The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure...
CVE-2026-56003HIGH8.8A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeSc...
CVE-2026-56002HIGH8.8A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers auth...
CVE-2026-57260HIGH7.8The application opened a PDF file containing an abnormal Unity 3D object. During parsing, the application incorrectly re...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now