2026 CVE Vulnerabilities
45,141 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56371 | MEDIUM | 5.3 | 0.2% | Jun 23, 2026 | ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture ... |
| CVE-2026-56301 | MEDIUM | 6.8 | 0.1% | Jun 23, 2026 | Nuxt 4.0.0 before 4.4.7 and 3.18.0 before 3.21.7, when running the development server (nuxt dev) on Linux, binds the vit... |
| CVE-2026-56263 | MEDIUM | 6.1 | 0.2% | Jun 23, 2026 | Crawl4AI before 0.8.7 contains a stored cross-site scripting vulnerability in the monitor dashboard that renders crawl U... |
| CVE-2026-56234 | MEDIUM | 6.9 | 0.2% | Jun 23, 2026 | Capgo before 12.128.2 contains a credential validation vulnerability in the POST /functions/v1/private/validate_password... |
| CVE-2026-4610 | MEDIUM | 6.4 | 0.2% | Jun 23, 2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scriptin... |
| CVE-2026-10857 | MEDIUM | 6.1 | 0.1% | Jun 23, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in AKIN Software Comp... |
| CVE-2026-4983 | MEDIUM | 5.4 | 0.2% | Jun 23, 2026 | Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content... |
| CVE-2026-8378 | MEDIUM | 5.4 | 0.1% | Jun 23, 2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not sanitise nor escape a filename submitted to the ... |
| CVE-2026-7842 | MEDIUM | 6.8 | 0.2% | Jun 23, 2026 | The Infility Global Infility Global WordPress plugin before 2.15.20 for WordPress does not sanitize or validate the orde... |
| CVE-2026-55655 | MEDIUM | 6.1 | 0.1% | Jun 23, 2026 | A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding ... |
| CVE-2026-55653 | MEDIUM | 6.5 | 0.3% | Jun 23, 2026 | A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group ... |
| CVE-2026-10651 | MEDIUM | 6.5 | 0.2% | Jun 23, 2026 | bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held the type-... |
| CVE-2026-10645 | MEDIUM | 5.5 | 0.2% | Jun 23, 2026 | The Zephyr ext2 filesystem driver (subsys/fs/ext2) trusted the on-disk directory entry fields de_rec_len and de_name_len... |
| CVE-2026-54236 | MEDIUM | 5.3 | 0.8% | Jun 22, 2026 | vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, the fix for CVE-2026-22778... |
| CVE-2026-54235 | MEDIUM | 6.5 | 0.3% | Jun 22, 2026 | vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, ll temperature validation ... |
| CVE-2026-54233 | MEDIUM | 6.5 | 0.2% | Jun 22, 2026 | vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, vLLM's /v1/audio/transcrip... |
| CVE-2026-47155 | MEDIUM | 6.5 | 0.1% | Jun 22, 2026 | vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, vLLM's revision pinning contr... |
| CVE-2026-56698 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 fail to validate script-capable URLs in the navigateTo open optio... |
| CVE-2026-56697 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 accept protocol-relative paths such as //evil.com in the reloadNu... |
| CVE-2026-56357 | MEDIUM | 5.3 | 0.2% | Jun 22, 2026 | n8n before 1.123.15 and 2.5.0 contains a webhook forgery vulnerability in the GitHub Webhook Trigger node that fails to ... |
| CVE-2026-56326 | MEDIUM | 6.1 | 0.2% | Jun 22, 2026 | Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 contain a server-side open redirect vulnerability in navigateTo t... |
| CVE-2026-56321 | MEDIUM | 6.9 | 0.3% | Jun 22, 2026 | Capgo (backend Supabase edge functions) before 12.128.2 does not apply the global authentication middleware to the GET /... |
| CVE-2026-56311 | MEDIUM | 6.9 | 0.3% | Jun 22, 2026 | Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.get_current_plan_max_org RPC function... |
| CVE-2026-56306 | MEDIUM | 6.4 | 0.3% | Jun 22, 2026 | Capgo before 12.128.2 contains a weak parsing vulnerability in the x-limited-key-id header that allows attackers to bypa... |
| CVE-2026-56255 | MEDIUM | 5.3 | 0.3% | Jun 22, 2026 | Capgo before 12.128.2 contains a denial of service vulnerability in the POST /app/demo endpoint that allows authenticate... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now