2026 CVE Vulnerabilities
45,138 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54301 | MEDIUM | 5.4 | 0.2% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with wo... |
| CVE-2026-48520 | MEDIUM | 6.1 | 0.2% | Jun 23, 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.10.0, the "Shareable Playgroun... |
| CVE-2026-44958 | MEDIUM | 5.4 | 0.3% | Jun 23, 2026 | An access control bypass allows an advertiser‑level user to activate or deactivate a banner in Revive Adserver 6.0.6 and... |
| CVE-2026-44957 | MEDIUM | 4.3 | 0.2% | Jun 23, 2026 | A missing access control check when invoking various modify methods in the XML‑RPC API of Revive Adserver 6.0.6 and earl... |
| CVE-2026-42867 | MEDIUM | 6.5 | 0.3% | Jun 23, 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to... |
| CVE-2026-34917 | MEDIUM | 4.3 | 0.3% | Jun 23, 2026 | Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication ... |
| CVE-2026-34915 | MEDIUM | 6.1 | 0.2% | Jun 23, 2026 | A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a l... |
| CVE-2026-34913 | MEDIUM | 4.3 | 0.2% | Jun 23, 2026 | A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Ads... |
| CVE-2026-34912 | MEDIUM | 4.3 | 0.2% | Jun 23, 2026 | A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive... |
| CVE-2026-56696 | MEDIUM | 5.4 | 0.2% | Jun 23, 2026 | OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel sende... |
| CVE-2026-56694 | MEDIUM | 5.4 | 0.2% | Jun 23, 2026 | NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration approval flow where hand... |
| CVE-2026-56693 | MEDIUM | 6.8 | 0.1% | Jun 23, 2026 | NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that pe... |
| CVE-2026-56692 | MEDIUM | 6.8 | 0.1% | Jun 23, 2026 | NanoClaw before 2.1.17 contains a symlink following vulnerability in forwardAttachedFiles that allows container-controll... |
| CVE-2026-55767 | MEDIUM | 5.8 | 0.1% | Jun 23, 2026 | Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain a... |
| CVE-2026-55766 | MEDIUM | 4.8 | 0.2% | Jun 23, 2026 | guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject C... |
| CVE-2026-55568 | MEDIUM | 5.9 | 0.1% | Jun 23, 2026 | Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by... |
| CVE-2026-54303 | MEDIUM | 5.4 | 0.2% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 2.24.0, an endpoint in the Meta and Microsoft Teams trigger... |
| CVE-2026-52673 | MEDIUM | 6.5 | 0.5% | Jun 23, 2026 | SQL Injection vulnerability in Cboard v.0.4.2 and before allows a remote attacker to execute arbitrary code via the getD... |
| CVE-2026-12969 | MEDIUM | 5.3 | 0.3% | Jun 23, 2026 | An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section re... |
| CVE-2026-11772 | MEDIUM | 5.1 | 0.4% | Jun 23, 2026 | DRIMO CMS is vulnerable to Reflected XSS via q parameter in searching functionality. An attacker can prepare an URL that... |
| CVE-2026-10609 | MEDIUM | 6.8 | 0.2% | Jun 23, 2026 | A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards Serv... |
| CVE-2026-56762 | MEDIUM | 6.9 | 0.2% | Jun 23, 2026 | Hono before 4.12.12 does not validate cookie names on the write path in the setCookie(), serialize(), and serializeSigne... |
| CVE-2026-56371 | MEDIUM | 5.3 | 0.2% | Jun 23, 2026 | ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture ... |
| CVE-2026-56301 | MEDIUM | 6.8 | 0.1% | Jun 23, 2026 | Nuxt 4.0.0 before 4.4.7 and 3.18.0 before 3.21.7, when running the development server (nuxt dev) on Linux, binds the vit... |
| CVE-2026-56263 | MEDIUM | 6.1 | 0.2% | Jun 23, 2026 | Crawl4AI before 0.8.7 contains a stored cross-site scripting vulnerability in the monitor dashboard that renders crawl U... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now