2026 CVE Vulnerabilities

43,311 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-72784MEDIUM6.9Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulne...
CVE-2026-72783MEDIUM6.2Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakne...
CVE-2026-72782HIGH7.1Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secre...
CVE-2026-72781HIGH8.8Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulnerabili...
CVE-2026-72780HIGH7.1Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey ...
CVE-2026-72779HIGH8.7Craft CMS 5.0.0-RC1 before 5.10.6 and 4.0.0-RC1 before 4.18.2 contain an arbitrary file read vulnerability. The create()...
CVE-2026-72778HIGH8.8Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code ex...
CVE-2026-72775MEDIUM5.8n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which interp...
CVE-2026-72774HIGH7.1n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenti...
CVE-2026-72773MEDIUM4.9n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in the @n8n/computer-use file-search (searc...
CVE-2026-72772HIGH8.9n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature. When...
CVE-2026-72771HIGH7.1n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when ...
CVE-2026-72770HIGH7.1n8n versions before 1.123.67 contain a path traversal vulnerability in the Git node's fetch, pull, and push-tags operati...
CVE-2026-72769MEDIUM6.1n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An aut...
CVE-2026-72768MEDIUM6.4n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node ...
CVE-2026-72767HIGH8.7n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code execution vulnerability in the Gi...
CVE-2026-72766HIGH8.2n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Emai...
CVE-2026-72765HIGH8.7n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated us...
CVE-2026-72764MEDIUM5.8n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected versions (...
CVE-2026-72763HIGH7.2n8n before 1.123.67, 2.31.5, and 2.32.1 validates credential-access only for a node's top-level credentials and not for ...
CVE-2026-72762HIGH7.7n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, w...
CVE-2026-72750MEDIUM5.3n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query ope...
CVE-2026-72749HIGH7.1n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the Edit Fields (Set) node. The ...
CVE-2026-72748CRITICAL9.1AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that a...
CVE-2026-72747HIGH7.2AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject maliciou...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now