2026 CVE Vulnerabilities

48,883 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-44029MEDIUM5.3An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "n...
CVE-2026-7783MEDIUM6.3A flaw has been found in CodeCanyon Perfex CRM up to 3.4.1. This vulnerability affects the function AbstractKanban::appl...
CVE-2026-7782MEDIUM6.3A vulnerability was detected in CodeCanyon Perfex CRM up to 3.4.1. This affects the function Clients::project of the fil...
CVE-2026-7781MEDIUM4.3A security vulnerability has been detected in Open5GS up to 2.7.7. Affected by this issue is the function udm_nudm_uecm_...
CVE-2026-7780MEDIUM4.3A weakness has been identified in Open5GS up to 2.7.7. Affected by this vulnerability is the function udm_state_operatio...
CVE-2026-7779MEDIUM4.3A security flaw has been discovered in Open5GS up to 2.7.7. Affected is the function udm_nudr_dr_handle_subscription_aut...
CVE-2026-42223MEDIUM6.5Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, the GetSettings API handler (api/sett...
CVE-2026-42220MEDIUM6.5Nginx UI is a web user interface for the Nginx web server. Prior to version 2.3.8, an authenticated user can call GET /a...
CVE-2026-42230MEDIUM6.1n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /mcp-oauth/regis...
CVE-2026-42228MEDIUM6.5n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket ...
CVE-2026-42227MEDIUM6.5n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated use...
CVE-2026-41686MEDIUM4.4Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From...
CVE-2026-42146MEDIUM5.5CImg Library is a C++ library for image processing. Prior to commit c3aacf5, the nb_colors field read from the BMP file ...
CVE-2026-42144MEDIUM6.1CImg Library is a C++ library for image processing. Prior to commit 4ca26bc, there is an integer overflow vulnerability ...
CVE-2026-42140MEDIUM4.4PlantUML Macro is a macro for rendering UML diagrams from simple textual schemes. Prior to version 2.4.1, the PlantUML M...
CVE-2026-42138MEDIUM6.1Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, a...
CVE-2026-42092MEDIUM6.5titra is an open source time tracking project. In version 0.99.52, the globalsettings Meteor publication returns all glo...
CVE-2026-42091MEDIUM6.5goshs is a SimpleHTTPServer written in Go. Prior to version 2.0.2, the PUT upload handler (httpserver/updown.go) lacks t...
CVE-2026-42086MEDIUM4.6OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ...
CVE-2026-42085MEDIUM4.3OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ...
CVE-2026-42052MEDIUM6Beets is the media library management system. Prior to version 2.10.0, the bundled web UI uses Underscore template inter...
CVE-2026-41572MEDIUM5.3Note Mark is an open-source note-taking application. Prior to version 0.19.3, after a note-mark owner soft-deletes a pub...
CVE-2026-42080MEDIUM4.6PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, there is an arbitrary fi...
CVE-2026-42078MEDIUM4.6PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable t...
CVE-2026-42077MEDIUM5.2Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a prototype pollution vulnerabilit...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now