2026 CVE Vulnerabilities

53,578 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-65596HIGH8.1n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based cr...
CVE-2026-65595HIGH8.8n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange module regardle...
CVE-2026-65594MEDIUM6.5n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was...
CVE-2026-65593MEDIUM5.4n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node...
CVE-2026-65592MEDIUM5.4n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator...
CVE-2026-65591HIGH8.8n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authentic...
CVE-2026-65590CRITICAL9.8n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/...
CVE-2026-65589MEDIUM6.5n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writin...
CVE-2026-65016HIGH8.8n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance...
CVE-2026-65015HIGH8.8n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-executio...
CVE-2026-65014MEDIUM5.3n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoi...
CVE-2026-61392MEDIUM5.3There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain ...
CVE-2026-61391HIGH7.2There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers ...
CVE-2026-61390HIGH7.7There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to ca...
CVE-2026-57600HIGH7.5Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers t...
CVE-2026-57599MEDIUM6.6There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the d...
CVE-2026-4773HIGH8.1Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA allows Authenticati...
CVE-2026-44192MEDIUM6.6A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as path traver...
CVE-2026-44190HIGH7.8A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) a...
CVE-2026-44189HIGH7.8A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injec...
CVE-2026-44187LOW3.3A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with ...
CVE-2026-16551MEDIUM6.9Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB module) allows Excessive Allocation. This issue affe...
CVE-2026-16544MEDIUM6.5A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are ...
CVE-2026-16473MEDIUM4.3A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted aud...
CVE-2026-14551HIGH8.8The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are v...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now