2026 CVE Vulnerabilities

48,284 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-54313HIGH7.7n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with workflow edit access cou...
CVE-2026-54312HIGH8.5n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with permission to create or ...
CVE-2026-54311HIGH7.7n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to...
CVE-2026-56815HIGH7.4pwnlift before d7a9544, in a privileged deployment, contains a symlink following vulnerability in the upload handler in ...
CVE-2026-35018HIGH8.8NetComm NF20MESH routers running firmware R6B031 and earlier contain an authenticated remote code execution vulnerabilit...
CVE-2026-56784HIGH8.6OpenRemote before 1.25.0 contains an insecure direct object reference (IDOR) vulnerability in the bulk alarm deletion en...
CVE-2026-56701HIGH7.1Grav before 2.0.0-beta.2 contains an XML external entity injection vulnerability in SVG file upload processing that allo...
CVE-2026-56322HIGH8.7Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /updates endpoint that res...
CVE-2026-56275HIGH7.1Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows attackers...
CVE-2026-56248HIGH8.7Cap-go capgo (capgo-backend) before 12.128.12 contains an unauthenticated denial-of-service vulnerability arising from t...
CVE-2026-56243HIGH8.6Capgo before 12.128.2 contains a security control bypass vulnerability where the PostgREST/RLS plane accepts plaintext A...
CVE-2026-56225HIGH8.7Capgo before 12.128.2 contains an authorization bypass vulnerability in its public API key management handlers (get/put/...
CVE-2026-56222HIGH8.6Capgo before 12.128.2 contains an authorization bypass vulnerability in POST /private/role_bindings that fails to verify...
CVE-2026-54892HIGH8.7Inefficient algorithmic complexity in Plug's nested-parameter decoder allows an unauthenticated remote attacker to cause...
CVE-2026-10711HIGH8.8Missing authentication for critical function vulnerability in AKIN Software Computer Import Export Industry and Trade Lt...
CVE-2026-10521HIGH8.6An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any user, ...
CVE-2026-8379HIGH7.5The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the file dow...
CVE-2026-8172HIGH7.1The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before reflecting it...
CVE-2026-8163HIGH8.8The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using t...
CVE-2026-11833HIGH8.2Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing t...
CVE-2026-10658HIGH7.1bt_iso_recv() in subsys/bluetooth/host/iso.c pulled the ISO SDU header (4 bytes) or, when the timestamp flag is set, the...
CVE-2026-54232HIGH8.8vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulner...
CVE-2026-53923HIGH7.5vLLM is an inference and serving engine for large language models (LLMs). From 0.5.5 until 0.23.1rc0, integer truncation...
CVE-2026-41523HIGH7.5vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security chec...
CVE-2026-56324HIGH8.8Capgo before 12.128.2 contains a rate limit bypass vulnerability in the channel_self endpoint that allows attackers to c...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now