2026 CVE Vulnerabilities

48,284 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-49402HIGH8.1Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.10, Deno's node:child_process implementation pro...
CVE-2026-49401HIGH8.4Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.14, Deno's permission system enforces filesystem...
CVE-2026-45135HIGH8.1Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitP...
CVE-2026-56116HIGH7.1dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement ro...
CVE-2026-56115HIGH8.8Bootimus through 0.1.70 contains a broken access control vulnerability that allows authenticated low-privileged users to...
CVE-2026-55446HIGH7.5Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.0.19, an attacker can send a /...
CVE-2026-55255HIGH8.4Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object...
CVE-2026-54308HIGH7.2n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, the MicrosoftAgent365Trigger and StripeT...
CVE-2026-54304HIGH7.7n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.1, an authenticated user with pe...
CVE-2026-50019HIGH7.4yt-dlp is a command-line audio/video downloader. From 2023.09.24 until 2026.06.09, if curl is used as an external downlo...
CVE-2026-49465HIGH7.7n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with pe...
CVE-2026-49444HIGH8.5n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with pe...
CVE-2026-45732HIGH8.1n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, the OAuth1 and OAuth2 credent...
CVE-2026-44959HIGH8.8A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑p...
CVE-2026-44790HIGH8.8n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with pe...
CVE-2026-34916HIGH8.8A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a l...
CVE-2026-34914HIGH8.3A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileg...
CVE-2026-33760HIGH8.8Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api/v1/monito...
CVE-2026-13007HIGH7.5Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive applicati...
CVE-2026-12958HIGH8.5Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust ...
CVE-2026-12957HIGH8.5Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may all...
CVE-2026-11940HIGH7.8tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink reference...
CVE-2026-56695HIGH7.1OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote ...
CVE-2026-56402HIGH7.1NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails ...
CVE-2026-54314HIGH7.5n8n is an open source workflow automation platform. Prior to 2.24.0, the Compression node's Decompress operation expande...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now