2026 CVE Vulnerabilities

64,785 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-59283CRITICAL9.1Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable...
CVE-2026-54687CRITICAL9.8n8n-nodes-sqlite3 is a node for operating a local SQLite database from n8n. Prior to 1.0.0, nodes/SqliteNode/v1/SqliteV1...
CVE-2026-53579CRITICAL9.3Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on ...
CVE-2026-53578CRITICAL9.3Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on ...
CVE-2026-48996CRITICAL9.3Trilium is an open-source hierarchical note-taking application. In versions up to and including 0.103.0, the default-on ...
CVE-2026-37072CRITICAL9.8Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-update...
CVE-2026-37071CRITICAL9.8Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4...
CVE-2026-37065CRITICAL9.1Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /vfm-admin/index.php?section=translations&ac...
CVE-2026-37007CRITICAL9.8A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to achieve code execution via ma...
CVE-2026-37006CRITICAL9.8A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker...
CVE-2026-37004CRITICAL9.8BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote att...
CVE-2026-37003CRITICAL9.8Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The PythonTools and Sh...
CVE-2026-35869CRITICAL9.8A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link R...
CVE-2026-35868CRITICAL9.8A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link R...
CVE-2026-30612CRITICAL9.8An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <=...
CVE-2026-19092CRITICAL9.8The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rend...
CVE-2026-18886CRITICAL10ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. Th...
CVE-2026-18885CRITICAL10ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnera...
CVE-2026-81826CRITICAL9.1Affected versions of Flowintel do not revoke existing authenticated sessions when a user’s password is changed. This m...
CVE-2026-81735CRITICAL10startServer.ts in the mcp-http-server package of UI-TARS-desktop defaulted its listen address to '::' when no host was g...
CVE-2026-81707CRITICAL9.8openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inj...
CVE-2026-81702CRITICAL9.8openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, al...
CVE-2026-81701CRITICAL9.8openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in ...
CVE-2026-81700CRITICAL9.8openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that ...
CVE-2026-81098CRITICAL9.1The Telnyx MCP server exposed its HTTP transport on every interface and did not require a caller credential. packages/mc...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now