2026 CVE Vulnerabilities
48,921 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-42230 | MEDIUM | 6.1 | 0.2% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /mcp-oauth/regis... |
| CVE-2026-42228 | MEDIUM | 6.5 | 0.4% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket ... |
| CVE-2026-42227 | MEDIUM | 6.5 | 0.2% | May 4, 2026 | n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated use... |
| CVE-2026-41686 | MEDIUM | 4.4 | 0.1% | May 4, 2026 | Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From... |
| CVE-2026-42146 | MEDIUM | 5.5 | 0.1% | May 4, 2026 | CImg Library is a C++ library for image processing. Prior to commit c3aacf5, the nb_colors field read from the BMP file ... |
| CVE-2026-42144 | MEDIUM | 6.1 | 0.1% | May 4, 2026 | CImg Library is a C++ library for image processing. Prior to commit 4ca26bc, there is an integer overflow vulnerability ... |
| CVE-2026-42140 | MEDIUM | 4.4 | 0.2% | May 4, 2026 | PlantUML Macro is a macro for rendering UML diagrams from simple textual schemes. Prior to version 2.4.1, the PlantUML M... |
| CVE-2026-42138 | MEDIUM | 6.1 | 0.2% | May 4, 2026 | Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, a... |
| CVE-2026-42092 | MEDIUM | 6.5 | 0.2% | May 4, 2026 | titra is an open source time tracking project. In version 0.99.52, the globalsettings Meteor publication returns all glo... |
| CVE-2026-42091 | MEDIUM | 6.5 | 0.2% | May 4, 2026 | goshs is a SimpleHTTPServer written in Go. Prior to version 2.0.2, the PUT upload handler (httpserver/updown.go) lacks t... |
| CVE-2026-42086 | MEDIUM | 4.6 | 0.2% | May 4, 2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2026-42085 | MEDIUM | 4.3 | 0.3% | May 4, 2026 | OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ... |
| CVE-2026-42052 | MEDIUM | 6 | 0.3% | May 4, 2026 | Beets is the media library management system. Prior to version 2.10.0, the bundled web UI uses Underscore template inter... |
| CVE-2026-41572 | MEDIUM | 5.3 | 0.2% | May 4, 2026 | Note Mark is an open-source note-taking application. Prior to version 0.19.3, after a note-mark owner soft-deletes a pub... |
| CVE-2026-42080 | MEDIUM | 4.6 | 0.2% | May 4, 2026 | PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, there is an arbitrary fi... |
| CVE-2026-42078 | MEDIUM | 4.6 | 0.2% | May 4, 2026 | PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable t... |
| CVE-2026-42077 | MEDIUM | 5.2 | 0.1% | May 4, 2026 | Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a prototype pollution vulnerabilit... |
| CVE-2026-38669 | MEDIUM | 6.1 | 0.1% | May 4, 2026 | wCMS v.1.4 is vulnerable to Cross Site Scripting (XSS) when creating a new blog. |
| CVE-2026-37458 | MEDIUM | 6.5 | 0.2% | May 4, 2026 | Missing input validation in the MP_REACH_NLRI component of FRRouting (FRR) stable/10.0 to stable/10.6 allows authenticat... |
| CVE-2026-6501 | MEDIUM | 5.3 | 0.2% | May 4, 2026 | Improper restriction of XML external entity reference vulnerability in ILM Informatique jOpenDocument allows Data Serial... |
| CVE-2026-6500 | MEDIUM | 4.8 | 0.1% | May 4, 2026 | Plaintext storage of a password vulnerability in ILM Informatique OpenConcerto allows Retrieve Embedded Sensitive Data. ... |
| CVE-2026-33523 | MEDIUM | 6.5 | 0.4% | May 4, 2026 | HTTP response splitting vulnerability in multiple Apache HTTP Server modules with untrusted or compromised backend serve... |
| CVE-2026-33007 | MEDIUM | 5.3 | 0.5% | May 4, 2026 | A NULL pointer dereference in the mod_authn_socache in Apache HTTP Server 2.4.66 and earlier allows an unauthenticated r... |
| CVE-2026-33006 | MEDIUM | 4.8 | 0.6% | May 4, 2026 | A timing attack against mod_auth_digest in Apache HTTP Server 2.4.66 allows a bypass of Digest authentication by a remot... |
| CVE-2026-34032 | MEDIUM | 5.3 | 0.5% | May 4, 2026 | Improper Null Termination, Out-of-bounds Read vulnerability in Apache HTTP Server. This issue affects Apache HTTP Serve... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now