2026 CVE Vulnerabilities
43,311 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-72784 | MEDIUM | 6.9 | — | Aug 11, 2026 | Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulne... |
| CVE-2026-72783 | MEDIUM | 6.2 | — | Aug 11, 2026 | Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakne... |
| CVE-2026-72782 | HIGH | 7.1 | — | Aug 11, 2026 | Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secre... |
| CVE-2026-72781 | HIGH | 8.8 | — | Aug 11, 2026 | Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulnerabili... |
| CVE-2026-72780 | HIGH | 7.1 | — | Aug 11, 2026 | Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey ... |
| CVE-2026-72779 | HIGH | 8.7 | — | Aug 11, 2026 | Craft CMS 5.0.0-RC1 before 5.10.6 and 4.0.0-RC1 before 4.18.2 contain an arbitrary file read vulnerability. The create()... |
| CVE-2026-72778 | HIGH | 8.8 | — | Aug 11, 2026 | Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code ex... |
| CVE-2026-72775 | MEDIUM | 5.8 | — | Aug 11, 2026 | n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which interp... |
| CVE-2026-72774 | HIGH | 7.1 | — | Aug 11, 2026 | n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenti... |
| CVE-2026-72773 | MEDIUM | 4.9 | — | Aug 11, 2026 | n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in the @n8n/computer-use file-search (searc... |
| CVE-2026-72772 | HIGH | 8.9 | — | Aug 11, 2026 | n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature. When... |
| CVE-2026-72771 | HIGH | 7.1 | — | Aug 11, 2026 | n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when ... |
| CVE-2026-72770 | HIGH | 7.1 | — | Aug 11, 2026 | n8n versions before 1.123.67 contain a path traversal vulnerability in the Git node's fetch, pull, and push-tags operati... |
| CVE-2026-72769 | MEDIUM | 6.1 | — | Aug 11, 2026 | n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An aut... |
| CVE-2026-72768 | MEDIUM | 6.4 | — | Aug 11, 2026 | n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node ... |
| CVE-2026-72767 | HIGH | 8.7 | — | Aug 11, 2026 | n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code execution vulnerability in the Gi... |
| CVE-2026-72766 | HIGH | 8.2 | — | Aug 11, 2026 | n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Emai... |
| CVE-2026-72765 | HIGH | 8.7 | — | Aug 11, 2026 | n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated us... |
| CVE-2026-72764 | MEDIUM | 5.8 | — | Aug 11, 2026 | n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected versions (... |
| CVE-2026-72763 | HIGH | 7.2 | — | Aug 11, 2026 | n8n before 1.123.67, 2.31.5, and 2.32.1 validates credential-access only for a node's top-level credentials and not for ... |
| CVE-2026-72762 | HIGH | 7.7 | — | Aug 11, 2026 | n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, w... |
| CVE-2026-72750 | MEDIUM | 5.3 | — | Aug 11, 2026 | n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query ope... |
| CVE-2026-72749 | HIGH | 7.1 | — | Aug 11, 2026 | n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the Edit Fields (Set) node. The ... |
| CVE-2026-72748 | CRITICAL | 9.1 | — | Aug 11, 2026 | AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that a... |
| CVE-2026-72747 | HIGH | 7.2 | — | Aug 11, 2026 | AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject maliciou... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now