2026 CVE Vulnerabilities

51,307 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-7788HIGH7.3A security flaw has been discovered in Axle-Bucamp MCP-Docusaurus up to 404bc028e15ec304c9a045528560f4b5f27a17e0. The af...
CVE-2026-7785HIGH7.3A security flaw has been discovered in A-G-U-P-T-A wireshark-mcp edaf604416fbc94a201b4043092d4a1b09a12275/400c3da70074f2...
CVE-2026-7784HIGH7.3A vulnerability has been found in RTGS2017 NagaAgent up to 5.1.0. This issue affects some unknown processing of the file...
CVE-2026-7791HIGH8.5Improper privilege management in the log rotation mechanism of the Skylight Workspace Config Service in Amazon WorkSpace...
CVE-2026-7776HIGH7.5Boundary Community Edition and Boundary Enterprise (“Boundary”) workers are vulnerable to a denial-of-service condition ...
CVE-2026-7768HIGH7.5@fastify/accepts-serializer cached serializer-selection results keyed by the request Accept header without a size limit ...
CVE-2026-6321HIGH7.5fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize()...
CVE-2026-41927HIGH8.3WDR201A WiFi Extender (HW V2.1, FW LFMZX28040922V1.02) contains a stack-based buffer overflow vulnerability in the firew...
CVE-2026-43964HIGH7.5Postfix before 3.8.16, 3.9 before 3.9.10, and 3.10 before 3.10.9 sometimes allows a buffer over-read and process crash v...
CVE-2026-42237HIGH8.8n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the fix for GHSA-f3f...
CVE-2026-42236HIGH7.5n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the MCP OAuth client...
CVE-2026-42234HIGH8.8n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated use...
CVE-2026-42232HIGH8.8n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated use...
CVE-2026-42231HIGH8.8n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the xml2js...
CVE-2026-42229HIGH8.8n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the SeaTab...
CVE-2026-42226HIGH7.5n8n is an open source workflow automation platform. Prior to versions 1.123.33 and 2.17.5, the dynamic-node-parameters e...
CVE-2026-42154HIGH7.5Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote ...
CVE-2026-42151HIGH7.5Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_...
CVE-2026-38751HIGH7.2OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionali...
CVE-2026-25863HIGH8.7Conditional Fields for Contact Form 7 WordPress plugin through version 2.7.2 contains an uncontrolled resource consumpti...
CVE-2026-43616HIGH7.8Detect-It-Easy prior to 3.21 contains a path traversal vulnerability that allows attackers to write arbitrary files to t...
CVE-2026-42088HIGH8.1OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ...
CVE-2026-42084HIGH8.1OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ...
CVE-2026-41471HIGH8.2The Easy PayPal Events & Tickets plugin for WordPress before version 1.4 contains an information disclosure vulnerabilit...
CVE-2026-37459HIGH7.5An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) v...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now