2026 CVE Vulnerabilities
45,449 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59257 | HIGH | 8.8 | 0.3% | Jul 8, 2026 | n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the legacy My... |
| CVE-2026-58656 | HIGH | 8.7 | — | Jul 8, 2026 | Grav API plugin before v1.0.0-rc.16 accepts JWT tokens via the ?token= URL query parameter and responds with Access-Cont... |
| CVE-2026-56776 | HIGH | 7.4 | 0.2% | Jul 8, 2026 | n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypass in the POST /workflows/{workflowId}/test-runs/n... |
| CVE-2026-56374 | HIGH | 7.1 | 0.1% | Jul 8, 2026 | ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary ch... |
| CVE-2026-56297 | HIGH | 8.1 | 0.3% | Jul 8, 2026 | FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcman_channel_close and dvcman_call_on_receive due to ... |
| CVE-2026-56250 | HIGH | 8.7 | — | Jul 8, 2026 | Capgo before 12.128.2 allows upload-scoped API keys to modify the mutable app_versions.r2_path field through PostgREST, ... |
| CVE-2026-56246 | HIGH | 8.1 | — | Jul 8, 2026 | Capgo before 12.128.2 contains a broken access control vulnerability in the organization management API where a scoped A... |
| CVE-2026-56226 | HIGH | 8.7 | — | Jul 8, 2026 | Capgo (Cap-go/capgo) before 12.128.2 exposes the Supabase PostgREST RPC function public.get_orgs_v6(userid uuid), which ... |
| CVE-2026-56220 | HIGH | 7.1 | — | Jul 8, 2026 | Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.manifest INSERT policy that allows re... |
| CVE-2026-56086 | HIGH | 8.8 | — | Jul 8, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-53482 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-44840 | HIGH | 7.5 | 0.5% | Jul 8, 2026 | Dgraph is an open source distributed GraphQL database. Prior to version 25.3.4, the `checkUserPassword` GraphQL query in... |
| CVE-2026-41122 | HIGH | 7.1 | — | Jul 8, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-22927 | HIGH | 7.8 | 0.2% | Jul 8, 2026 | Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability. |
| CVE-2026-15053 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | Tanium addressed a denial of service vulnerability in Tanium Server. |
| CVE-2026-15035 | HIGH | 7.8 | 0.6% | Jul 8, 2026 | A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm... |
| CVE-2026-6820 | HIGH | 7.2 | — | Jul 8, 2026 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ema... |
| CVE-2026-5356 | HIGH | 7.5 | — | Jul 8, 2026 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Improper Input... |
| CVE-2026-6854 | HIGH | 7.5 | — | Jul 8, 2026 | The My Calendar – Accessible Event Manager plugin for WordPress is vulnerable to time-based blind SQL Injection via the ... |
| CVE-2026-6818 | HIGH | 7.2 | — | Jul 8, 2026 | The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'spe... |
| CVE-2026-6230 | HIGH | 7.5 | — | Jul 8, 2026 | The Tainacan plugin for WordPress is vulnerable to time-based blind SQL Injection via the 'geoquery' parameter in all ve... |
| CVE-2026-3688 | HIGH | 8.1 | — | Jul 8, 2026 | The WCFM Membership – WooCommerce Memberships for Multivendor Marketplace plugin for WordPress is vulnerable to Insecure... |
| CVE-2026-56003 | HIGH | 8.8 | 0.6% | Jul 8, 2026 | A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeSc... |
| CVE-2026-56002 | HIGH | 8.8 | 0.5% | Jul 8, 2026 | A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers auth... |
| CVE-2026-57260 | HIGH | 7.8 | 0.1% | Jul 8, 2026 | The application opened a PDF file containing an abnormal Unity 3D object. During parsing, the application incorrectly re... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now