2026 CVE Vulnerabilities

45,141 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-56371MEDIUM5.3ImageMagick before 7.1.2-15 and 6.9.13-40 contains a memory leak in coders/txt.c when processing TXT files with texture ...
CVE-2026-56301MEDIUM6.8Nuxt 4.0.0 before 4.4.7 and 3.18.0 before 3.21.7, when running the development server (nuxt dev) on Linux, binds the vit...
CVE-2026-56263MEDIUM6.1Crawl4AI before 0.8.7 contains a stored cross-site scripting vulnerability in the monitor dashboard that renders crawl U...
CVE-2026-56234MEDIUM6.9Capgo before 12.128.2 contains a credential validation vulnerability in the POST /functions/v1/private/validate_password...
CVE-2026-4610MEDIUM6.4The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scriptin...
CVE-2026-10857MEDIUM6.1Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in AKIN Software Comp...
CVE-2026-4983MEDIUM5.4Open VSX Registry does not sanitize SVG files uploaded as extension icons prior to storage, and serves them with Content...
CVE-2026-8378MEDIUM5.4The Frontend File Manager Plugin WordPress plugin through 23.6 does not sanitise nor escape a filename submitted to the ...
CVE-2026-7842MEDIUM6.8The Infility Global Infility Global WordPress plugin before 2.15.20 for WordPress does not sanitize or validate the orde...
CVE-2026-55655MEDIUM6.1A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding ...
CVE-2026-55653MEDIUM6.5A flaw was found in OpenSSH. A malicious SSH server can exploit a double free vulnerability in the Diffie-Hellman Group ...
CVE-2026-10651MEDIUM6.5bt_sdp_parse_attribute() in subsys/bluetooth/host/classic/sdp.c validated only that the SDP record buffer held the type-...
CVE-2026-10645MEDIUM5.5The Zephyr ext2 filesystem driver (subsys/fs/ext2) trusted the on-disk directory entry fields de_rec_len and de_name_len...
CVE-2026-54236MEDIUM5.3vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, the fix for CVE-2026-22778...
CVE-2026-54235MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, ll temperature validation ...
CVE-2026-54233MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.23.1rc0, vLLM's /v1/audio/transcrip...
CVE-2026-47155MEDIUM6.5vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, vLLM's revision pinning contr...
CVE-2026-56698MEDIUM6.1Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 fail to validate script-capable URLs in the navigateTo open optio...
CVE-2026-56697MEDIUM6.1Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 accept protocol-relative paths such as //evil.com in the reloadNu...
CVE-2026-56357MEDIUM5.3n8n before 1.123.15 and 2.5.0 contains a webhook forgery vulnerability in the GitHub Webhook Trigger node that fails to ...
CVE-2026-56326MEDIUM6.1Nuxt versions 4.0.0 before 4.4.7 and 3.x before 3.21.7 contain a server-side open redirect vulnerability in navigateTo t...
CVE-2026-56321MEDIUM6.9Capgo (backend Supabase edge functions) before 12.128.2 does not apply the global authentication middleware to the GET /...
CVE-2026-56311MEDIUM6.9Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.get_current_plan_max_org RPC function...
CVE-2026-56306MEDIUM6.4Capgo before 12.128.2 contains a weak parsing vulnerability in the x-limited-key-id header that allows attackers to bypa...
CVE-2026-56255MEDIUM5.3Capgo before 12.128.2 contains a denial of service vulnerability in the POST /app/demo endpoint that allows authenticate...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now