2026 CVE Vulnerabilities

50,941 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-69256CRITICAL9.4Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent no...
CVE-2026-69255CRITICAL9.2Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in...
CVE-2026-64634HIGH8.4A vulnerability allowing local privilege escalation to the Reporter service context.
CVE-2026-64633CRITICAL10A vulnerability allowing remote unauthenticated code execution on the agent host.
CVE-2026-64631HIGH8.5A vulnerability allowing a low-privileged user to inject SQL and extract database contents.
CVE-2026-64630MEDIUM5.3A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.
CVE-2026-63456CRITICAL9.8Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated ...
CVE-2026-63455CRITICAL9.8Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated ...
CVE-2026-58075HIGH8.7A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leverag...
CVE-2026-58074HIGH8.6A vulnerability allowing a high-privileged user to execute arbitrary code on the server.
CVE-2026-58073CRITICAL9.5A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent an...
CVE-2026-58072CRITICAL9A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead...
CVE-2026-58071HIGH8.2A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance A...
CVE-2026-58067HIGH8.7A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause ...
CVE-2026-56848HIGH7.5A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_m...
CVE-2026-48121MEDIUM6.7@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for sto...
CVE-2026-18787HIGH8.8A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the fi...
CVE-2026-18785MEDIUM5.3A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Cli...
CVE-2026-18784MEDIUM5.3A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute ...
CVE-2026-18775MEDIUM6.3A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browse...
CVE-2026-18774MEDIUM6.3A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file ag...
CVE-2026-15920MEDIUM6.1An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field(...
CVE-2026-15830MEDIUM5.3An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome...
CVE-2026-15337MEDIUM5.3An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()...
CVE-2026-15314HIGH7.5Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HT...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now