2026 CVE Vulnerabilities
48,284 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54313 | HIGH | 7.7 | 0.3% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with workflow edit access cou... |
| CVE-2026-54312 | HIGH | 8.5 | 0.3% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with permission to create or ... |
| CVE-2026-54311 | HIGH | 7.7 | 0.3% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to... |
| CVE-2026-56815 | HIGH | 7.4 | 0.1% | Jun 23, 2026 | pwnlift before d7a9544, in a privileged deployment, contains a symlink following vulnerability in the upload handler in ... |
| CVE-2026-35018 | HIGH | 8.8 | 0.7% | Jun 23, 2026 | NetComm NF20MESH routers running firmware R6B031 and earlier contain an authenticated remote code execution vulnerabilit... |
| CVE-2026-56784 | HIGH | 8.6 | 0.3% | Jun 23, 2026 | OpenRemote before 1.25.0 contains an insecure direct object reference (IDOR) vulnerability in the bulk alarm deletion en... |
| CVE-2026-56701 | HIGH | 7.1 | 0.2% | Jun 23, 2026 | Grav before 2.0.0-beta.2 contains an XML external entity injection vulnerability in SVG file upload processing that allo... |
| CVE-2026-56322 | HIGH | 8.7 | 0.3% | Jun 23, 2026 | Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /updates endpoint that res... |
| CVE-2026-56275 | HIGH | 7.1 | 0.2% | Jun 23, 2026 | Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows attackers... |
| CVE-2026-56248 | HIGH | 8.7 | 0.4% | Jun 23, 2026 | Cap-go capgo (capgo-backend) before 12.128.12 contains an unauthenticated denial-of-service vulnerability arising from t... |
| CVE-2026-56243 | HIGH | 8.6 | 0.3% | Jun 23, 2026 | Capgo before 12.128.2 contains a security control bypass vulnerability where the PostgREST/RLS plane accepts plaintext A... |
| CVE-2026-56225 | HIGH | 8.7 | 0.3% | Jun 23, 2026 | Capgo before 12.128.2 contains an authorization bypass vulnerability in its public API key management handlers (get/put/... |
| CVE-2026-56222 | HIGH | 8.6 | 0.4% | Jun 23, 2026 | Capgo before 12.128.2 contains an authorization bypass vulnerability in POST /private/role_bindings that fails to verify... |
| CVE-2026-54892 | HIGH | 8.7 | 0.7% | Jun 23, 2026 | Inefficient algorithmic complexity in Plug's nested-parameter decoder allows an unauthenticated remote attacker to cause... |
| CVE-2026-10711 | HIGH | 8.8 | 0.2% | Jun 23, 2026 | Missing authentication for critical function vulnerability in AKIN Software Computer Import Export Industry and Trade Lt... |
| CVE-2026-10521 | HIGH | 8.6 | 0.3% | Jun 23, 2026 | An high privileged remote attacker can access a hidden configuration method, that should not be accessible by any user, ... |
| CVE-2026-8379 | HIGH | 7.5 | 0.2% | Jun 23, 2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly enforce its nonce check on the file dow... |
| CVE-2026-8172 | HIGH | 7.1 | 0.2% | Jun 23, 2026 | The Simple Basic Contact Form WordPress plugin through 20250114 does not escape user-supplied input before reflecting it... |
| CVE-2026-8163 | HIGH | 8.8 | 0.2% | Jun 23, 2026 | The Infility Global WordPress plugin before 2.15.19 does not properly sanitize and escape some parameters before using t... |
| CVE-2026-11833 | HIGH | 8.2 | 0.2% | Jun 23, 2026 | Overview: A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing t... |
| CVE-2026-10658 | HIGH | 7.1 | 0.2% | Jun 23, 2026 | bt_iso_recv() in subsys/bluetooth/host/iso.c pulled the ISO SDU header (4 bytes) or, when the timestamp flag is set, the... |
| CVE-2026-54232 | HIGH | 8.8 | 0.3% | Jun 22, 2026 | vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.1, the vLLM Dockerfile is vulner... |
| CVE-2026-53923 | HIGH | 7.5 | 0.3% | Jun 22, 2026 | vLLM is an inference and serving engine for large language models (LLMs). From 0.5.5 until 0.23.1rc0, integer truncation... |
| CVE-2026-41523 | HIGH | 7.5 | 0.7% | Jun 22, 2026 | vLLM is an inference and serving engine for large language models (LLMs). Prior to 0.22.0, an assert-based security chec... |
| CVE-2026-56324 | HIGH | 8.8 | 0.3% | Jun 22, 2026 | Capgo before 12.128.2 contains a rate limit bypass vulnerability in the channel_self endpoint that allows attackers to c... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now