2026 CVE Vulnerabilities

51,327 CVEs published in 2026.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2026-42231HIGH8.8n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the xml2js...
CVE-2026-42229HIGH8.8n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the SeaTab...
CVE-2026-42226HIGH7.5n8n is an open source workflow automation platform. Prior to versions 1.123.33 and 2.17.5, the dynamic-node-parameters e...
CVE-2026-42154HIGH7.5Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the remote ...
CVE-2026-42151HIGH7.5Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_...
CVE-2026-38751HIGH7.2OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionali...
CVE-2026-25863HIGH8.7Conditional Fields for Contact Form 7 WordPress plugin through version 2.7.2 contains an uncontrolled resource consumpti...
CVE-2026-43616HIGH7.8Detect-It-Easy prior to 3.21 contains a path traversal vulnerability that allows attackers to write arbitrary files to t...
CVE-2026-42088HIGH8.1OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ...
CVE-2026-42084HIGH8.1OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. ...
CVE-2026-41471HIGH8.2The Easy PayPal Events & Tickets plugin for WordPress before version 1.4 contains an information disclosure vulnerabilit...
CVE-2026-37459HIGH7.5An integer underflow in FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) v...
CVE-2026-32834HIGH8.7Easy PayPal Events & Tickets plugin for WordPress before version 1.4 contains a hardcoded authentication bypass vulnerab...
CVE-2026-29004HIGH8.1BusyBox before commit 42202bf contains a heap buffer overflow vulnerability in the DHCPv6 client (udhcpc6) DNS_SERVERS o...
CVE-2026-0073HIGH8.8In adbd_tls_verify_cert of auth.cpp, there is a possible bypass of wireless ADB mutual authentication due to a logic err...
CVE-2026-42440HIGH7.5OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader  Versions Affected:  before...
CVE-2026-42375HIGH8.8D-Link DIR-600L Hardware Revision A1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daem...
CVE-2026-42374HIGH8.8D-Link DIR-600L Hardware Revision B1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daem...
CVE-2026-42373HIGH8.8D-Link DIR-605L Hardware Revision B2 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet...
CVE-2026-42372HIGH8.8D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet...
CVE-2026-42079HIGH8.6PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable t...
CVE-2026-42075HIGH8.1Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a path traversal vulnerability in ...
CVE-2026-37461HIGH7.5An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial ...
CVE-2026-29514HIGH8.8NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environ...
CVE-2026-25266HIGH7.8Memory corruption while processing IOCTL command when device is in power-save state.

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now