2026 CVE Vulnerabilities

43,347 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-72768MEDIUM6.4n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node ...
CVE-2026-72767HIGH8.7n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code execution vulnerability in the Gi...
CVE-2026-72766HIGH8.2n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Emai...
CVE-2026-72765HIGH8.7n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated us...
CVE-2026-72764MEDIUM5.8n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected versions (...
CVE-2026-72763HIGH7.2n8n before 1.123.67, 2.31.5, and 2.32.1 validates credential-access only for a node's top-level credentials and not for ...
CVE-2026-72762HIGH7.7n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, w...
CVE-2026-72750MEDIUM5.3n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query ope...
CVE-2026-72749HIGH7.1n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the Edit Fields (Set) node. The ...
CVE-2026-72748CRITICAL9.1AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that a...
CVE-2026-72747HIGH7.2AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject maliciou...
CVE-2026-72746Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-20...
CVE-2026-72745Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-20...
CVE-2026-72744MEDIUM6.9Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure vulnerability in the ...
CVE-2026-69109HIGH8.7A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is v...
CVE-2026-69108HIGH8.3A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The affected application is v...
CVE-2026-64629HIGH7.8A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.235), Parasolid V38.1 (All versions < V38.1...
CVE-2026-59701HIGH7.8A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contains a...
CVE-2026-59700HIGH7.8A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contains a...
CVE-2026-59693MEDIUM5.3A vulnerability has been identified in Desigo DXR2 (All versions < V01.21.233.16-7862), Desigo PXC3 (All versions < V01....
CVE-2026-59086HIGH7.8A vulnerability has been identified in Simcenter Femap (All versions < V2606), Simcenter Nastran (All versions < V2606)....
CVE-2026-58115CRITICAL10A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running In...
CVE-2026-57263HIGH7A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). The project password feature in the affec...
CVE-2026-57262HIGH7A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). Affected products use a static, hardcoded...
CVE-2026-50064HIGH7.8A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versi...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now