2026 CVE Vulnerabilities

48,921 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-42230MEDIUM6.1n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /mcp-oauth/regis...
CVE-2026-42228MEDIUM6.5n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket ...
CVE-2026-42227MEDIUM6.5n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated use...
CVE-2026-41686MEDIUM4.4Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From...
CVE-2026-42146MEDIUM5.5CImg Library is a C++ library for image processing. Prior to commit c3aacf5, the nb_colors field read from the BMP file ...
CVE-2026-42144MEDIUM6.1CImg Library is a C++ library for image processing. Prior to commit 4ca26bc, there is an integer overflow vulnerability ...
CVE-2026-42140MEDIUM4.4PlantUML Macro is a macro for rendering UML diagrams from simple textual schemes. Prior to version 2.4.1, the PlantUML M...
CVE-2026-42138MEDIUM6.1Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, a...
CVE-2026-42092MEDIUM6.5titra is an open source time tracking project. In version 0.99.52, the globalsettings Meteor publication returns all glo...
CVE-2026-42091MEDIUM6.5goshs is a SimpleHTTPServer written in Go. Prior to version 2.0.2, the PUT upload handler (httpserver/updown.go) lacks t...
CVE-2026-42086MEDIUM4.6OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ...
CVE-2026-42085MEDIUM4.3OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ...
CVE-2026-42052MEDIUM6Beets is the media library management system. Prior to version 2.10.0, the bundled web UI uses Underscore template inter...
CVE-2026-41572MEDIUM5.3Note Mark is an open-source note-taking application. Prior to version 0.19.3, after a note-mark owner soft-deletes a pub...
CVE-2026-42080MEDIUM4.6PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, there is an arbitrary fi...
CVE-2026-42078MEDIUM4.6PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable t...
CVE-2026-42077MEDIUM5.2Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a prototype pollution vulnerabilit...
CVE-2026-38669MEDIUM6.1wCMS v.1.4 is vulnerable to Cross Site Scripting (XSS) when creating a new blog.
CVE-2026-37458MEDIUM6.5Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticat...
CVE-2026-6501MEDIUM5.3Improper restriction of XML external entity reference vulnerability in ILM Informatique jOpenDocument allows Data Serial...
CVE-2026-6500MEDIUM4.8Plaintext storage of a password vulnerability in ILM Informatique OpenConcerto allows Retrieve Embedded Sensitive Data. ...
CVE-2026-33523MEDIUM6.5HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend serve...
CVE-2026-33007MEDIUM5.3A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated r...
CVE-2026-33006MEDIUM4.8A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remot...
CVE-2026-34032MEDIUM5.3Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Serve...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now