2026 CVE Vulnerabilities

45,138 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-54301MEDIUM5.4n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with wo...
CVE-2026-48520MEDIUM6.1Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.10.0, the "Shareable Playgroun...
CVE-2026-44958MEDIUM5.4An access control bypass allows an advertiser‑level user to activate or deactivate a banner in Revive Adserver 6.0.6 and...
CVE-2026-44957MEDIUM4.3A missing access control check when invoking various modify methods in the XML‑RPC API of Revive Adserver 6.0.6 and earl...
CVE-2026-42867MEDIUM6.5Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to...
CVE-2026-34917MEDIUM4.3Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication ...
CVE-2026-34915MEDIUM6.1A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a l...
CVE-2026-34913MEDIUM4.3A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Ads...
CVE-2026-34912MEDIUM4.3A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive...
CVE-2026-56696MEDIUM5.4OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel sende...
CVE-2026-56694MEDIUM5.4NanoClaw before 2.1.0 contains a privilege escalation vulnerability in the channel-registration approval flow where hand...
CVE-2026-56693MEDIUM6.8NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the create_agent delivery-action handler that pe...
CVE-2026-56692MEDIUM6.8NanoClaw before 2.1.17 contains a symlink following vulnerability in forwardAttachedFiles that allows container-controll...
CVE-2026-55767MEDIUM5.8Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain a...
CVE-2026-55766MEDIUM4.8guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject C...
CVE-2026-55568MEDIUM5.9Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by...
CVE-2026-54303MEDIUM5.4n8n is an open source workflow automation platform. Prior to 2.24.0, an endpoint in the Meta and Microsoft Teams trigger...
CVE-2026-52673MEDIUM6.5SQL Injection vulnerability in Cboard v.0.4.2 and before allows a remote attacker to execute arbitrary code via the getD...
CVE-2026-12969MEDIUM5.3An out-of-bounds read vulnerability exists in dnsmasq's find_soa() function in src/rfc1035.c. When parsing NS section re...
CVE-2026-11772MEDIUM5.1DRIMO CMS is vulnerable to Reflected XSS via q parameter in searching functionality. An attacker can prepare an URL that...
CVE-2026-10609MEDIUM6.8A missing authorization flaw was found in the OpenShift Cluster Logging Operator. The operator creates and forwards Serv...
CVE-2026-56762MEDIUM6.9Hono before 4.12.12 does not validate cookie names on the write path in the setCookie(), serialize(), and serializeSigne...
CVE-2026-56371MEDIUM5.3ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture ...
CVE-2026-56301MEDIUM6.8Nuxt 4.0.0 before 4.4.7 and 3.18.0 before 3.21.7, when running the development server (nuxt dev) on Linux, binds the vit...
CVE-2026-56263MEDIUM6.1Crawl4AI before 0.8.7 contains a stored cross-site scripting vulnerability in the monitor dashboard that renders crawl U...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now