2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59283 | CRITICAL | 9.1 | 0.4% | Aug 27, 2026 | Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable... |
| CVE-2026-54687 | CRITICAL | 9.8 | 0.5% | Aug 27, 2026 | n8n-nodes-sqlite3 is a node for operating a local SQLite database from n8n. Prior to 1.0.0, nodes/SqliteNode/v1/SqliteV1... |
| CVE-2026-53579 | CRITICAL | 9.3 | 0.2% | Aug 27, 2026 | Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on ... |
| CVE-2026-53578 | CRITICAL | 9.3 | 0.2% | Aug 27, 2026 | Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on ... |
| CVE-2026-48996 | CRITICAL | 9.3 | 0.2% | Aug 27, 2026 | Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on ... |
| CVE-2026-37072 | CRITICAL | 9.8 | 0.2% | Aug 27, 2026 | Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-update... |
| CVE-2026-37071 | CRITICAL | 9.8 | 0.2% | Aug 27, 2026 | Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4... |
| CVE-2026-37065 | CRITICAL | 9.1 | 0.2% | Aug 27, 2026 | Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /vfm-admin/index.php?section=translations&ac... |
| CVE-2026-37007 | CRITICAL | 9.8 | 0.3% | Aug 27, 2026 | A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to achieve code execution via ma... |
| CVE-2026-37006 | CRITICAL | 9.8 | 0.6% | Aug 27, 2026 | A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker... |
| CVE-2026-37004 | CRITICAL | 9.8 | 0.2% | Aug 27, 2026 | BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote att... |
| CVE-2026-37003 | CRITICAL | 9.8 | 1.6% | Aug 27, 2026 | Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The PythonTools and Sh... |
| CVE-2026-35869 | CRITICAL | 9.8 | 1.3% | Aug 27, 2026 | A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link R... |
| CVE-2026-35868 | CRITICAL | 9.8 | 1.4% | Aug 27, 2026 | A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link R... |
| CVE-2026-30612 | CRITICAL | 9.8 | 0.3% | Aug 27, 2026 | An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <=... |
| CVE-2026-19092 | CRITICAL | 9.8 | 0.4% | Aug 27, 2026 | The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rend... |
| CVE-2026-18886 | CRITICAL | 10 | 0.2% | Aug 27, 2026 | ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. Th... |
| CVE-2026-18885 | CRITICAL | 10 | 0.4% | Aug 27, 2026 | ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnera... |
| CVE-2026-81826 | CRITICAL | 9.1 | 0.3% | Aug 27, 2026 | Affected versions of Flowintel do not revoke existing authenticated sessions when a user’s password is changed. This m... |
| CVE-2026-81735 | CRITICAL | 10 | 0.5% | Aug 27, 2026 | startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was g... |
| CVE-2026-81707 | CRITICAL | 9.8 | 0.4% | Aug 27, 2026 | openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inj... |
| CVE-2026-81702 | CRITICAL | 9.8 | 0.1% | Aug 27, 2026 | openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, al... |
| CVE-2026-81701 | CRITICAL | 9.8 | 0.3% | Aug 27, 2026 | openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in ... |
| CVE-2026-81700 | CRITICAL | 9.8 | 0.3% | Aug 27, 2026 | openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that ... |
| CVE-2026-81098 | CRITICAL | 9.1 | 0.7% | Aug 27, 2026 | The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mc... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now