2026 CVE Vulnerabilities

56,189 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-13181HIGH8.1In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName process...
CVE-2026-8152CRITICAL9.3Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) atta...
CVE-2026-44191HIGH7.8A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) a...
CVE-2026-16270MEDIUM6.9Open Mercato does not validate regex rules. An attacker with privileges to create the regex rule can add an unsafe regex...
CVE-2026-65603HIGH8.8The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated pr...
CVE-2026-65602HIGH8.8Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRo...
CVE-2026-65601MEDIUM5.3Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider....
CVE-2026-65600MEDIUM5.3Traefik versions <= v2.11.51, >= v3.6.0 <= v3.6.22, and >= v3.7.0 <= v3.7.6 contain an authentication bypass via path tr...
CVE-2026-65599MEDIUM6.5n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Goo...
CVE-2026-65598HIGH7.5n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows a...
CVE-2026-65597MEDIUM5.4n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting vulnerability in the...
CVE-2026-65596HIGH8.1n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based cr...
CVE-2026-65595HIGH8.8n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange module regardle...
CVE-2026-65594MEDIUM6.5n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was...
CVE-2026-65593MEDIUM5.4n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a server-side request forgery vulnerability in the dynamic-node...
CVE-2026-65592MEDIUM5.4n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator...
CVE-2026-65591HIGH8.8n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authentic...
CVE-2026-65590CRITICAL9.8n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/...
CVE-2026-65589MEDIUM6.5n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writin...
CVE-2026-65016HIGH8.8n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance...
CVE-2026-65015HIGH8.8n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-executio...
CVE-2026-65014MEDIUM5.3n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoi...
CVE-2026-61392MEDIUM5.3There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain ...
CVE-2026-61391HIGH7.2There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers ...
CVE-2026-61390HIGH7.7There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to ca...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now