2026 CVE Vulnerabilities

46,941 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-24699HIGH7.2An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with f...
CVE-2026-24698HIGH7.2An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco RV130/...
CVE-2026-24697HIGH7.2An OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV130W wi...
CVE-2026-15067HIGH8.8Snowflake Terraform Provider versions prior to 2.18.0 contain several security vulnerabilities, including SQL injection ...
CVE-2026-10708HIGH7.5This vulnerability enables large‑scale data harvesting without requiring app‑specific secrets. A single request to a min...
CVE-2026-10706HIGH7.5In Adalo’s no-code app builder, (Versions 1 and 2) the attackers may extract full user records and correlate user behavi...
CVE-2026-10699HIGH7.5Missing release of memory after effective lifetime vulnerability in Progress MOVEit Transfer (Custom Reports modules). ...
CVE-2026-10698HIGH7.2Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Report...
CVE-2026-59257HIGH8.8n8n before 1.123.61, 2.x before 2.27.4, and 2.28.x before 2.28.1 contains a SQL injection vulnerability in the legacy My...
CVE-2026-58656HIGH8.7Grav API plugin before v1.0.0-rc.16 accepts JWT tokens via the ?token= URL query parameter and responds with Access-Cont...
CVE-2026-56776HIGH7.4n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypass in the POST /workflows/{workflowId}/test-runs/n...
CVE-2026-56374HIGH7.1ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary ch...
CVE-2026-56297HIGH8.1FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcman_channel_close and dvcman_call_on_receive due to ...
CVE-2026-56250HIGH8.7Capgo before 12.128.2 allows upload-scoped API keys to modify the mutable app_versions.r2_path field through PostgREST, ...
CVE-2026-56246HIGH8.1Capgo before 12.128.2 contains a broken access control vulnerability in the organization management API where a scoped A...
CVE-2026-56226HIGH8.7Capgo (Cap-go/capgo) before 12.128.2 exposes the Supabase PostgREST RPC function public.get_orgs_v6(userid uuid), which ...
CVE-2026-56220HIGH7.1Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.manifest INSERT policy that allows re...
CVE-2026-56086HIGH8.8Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-53482HIGH7.5Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-44840HIGH7.5Dgraph is an open source distributed GraphQL database. Prior to version 25.3.4, the `checkUserPassword` GraphQL query in...
CVE-2026-41122HIGH7.1Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r...
CVE-2026-22927HIGH7.8Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability.
CVE-2026-15053HIGH7.5Tanium addressed a denial of service vulnerability in Tanium Server.
CVE-2026-15035HIGH7.8A vulnerability was found in bentoml OpenLLM 0.6.30. This affects the function async_run_command of the file src/openllm...
CVE-2026-6820HIGH7.2The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ema...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now