2026 CVE Vulnerabilities

48,297 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-56323HIGH8.7Capgo before 12.128.2 contains an information disclosure vulnerability in the /functions/v1/channel_self endpoint that a...
CVE-2026-56314HIGH7.1Capgo before 12.128.12 fails to filter deleted app versions when joining channels during /updates resolution, allowing d...
CVE-2026-56280HIGH7.1Cap-go before 12.128.2 contains a privilege inversion vulnerability in GET /build/logs/:jobId that allows read-only API ...
CVE-2026-56268HIGH7.7Flowise before 3.1.2 contains an information disclosure vulnerability in the /api/v1/chatflows/apikey/:apikey endpoint. ...
CVE-2026-56266HIGH8.6Crawl4AI before 0.8.7 contains a server-side request forgery vulnerability in the /crawl, /crawl/stream, /md, and /llm e...
CVE-2026-56221HIGH7.1Cap-go before 12.128.2 contains multiple SQL injection vulnerabilities in cloudflare.ts where user-controlled values fro...
CVE-2026-55409HIGH7.6Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.53, a disabl...
CVE-2026-54281HIGH8.7Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.24, an authentication bypass v...
CVE-2026-48517HIGH7.5MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's typeless deseria...
CVE-2026-48516HIGH7.5MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, InterfaceLookupFormatter<TKey,TElemen...
CVE-2026-48515HIGH7.5MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's multi-dimensiona...
CVE-2026-48514HIGH7.5MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, UnsafeBlitFormatterBase<T>.Deserializ...
CVE-2026-48513HIGH7.5MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, runtime-generated union deserializers...
CVE-2026-48512HIGH7.5MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePack-CSharp's JSON conversion ...
CVE-2026-48511HIGH7.5MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, ExpandoObjectFormatter.Deserialize po...
CVE-2026-48510HIGH7.5MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, when MessagePack-CSharp decompresses ...
CVE-2026-48506HIGH7.5MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.TrySkip() recursive...
CVE-2026-48505HIGH7.4Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5...
CVE-2026-48502HIGH7.5MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, MessagePackReader.ReadDateTime() can ...
CVE-2026-48109HIGH8.2MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, A vulnerability exists in the optiona...
CVE-2026-55603HIGH7.5http-proxy-middleware is node.js http-proxy middleware. From 3.0.4 until 3.0.7 and 4.1.1, fixRequestBody() is the librar...
CVE-2026-39904HIGH7.1Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to ...
CVE-2026-44274HIGH7.8Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Link Resolution Before File Access vul...
CVE-2026-44272HIGH8.8Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements use...
CVE-2026-44271HIGH8.8Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain an Improper Neutralization of Special Elements use...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now