2026 CVE Vulnerabilities

56,195 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-65016HIGH8.8n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance...
CVE-2026-65015HIGH8.8n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-executio...
CVE-2026-65014MEDIUM5.3n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoi...
CVE-2026-61392MEDIUM5.3There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain ...
CVE-2026-61391HIGH7.2There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers ...
CVE-2026-61390HIGH7.7There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to ca...
CVE-2026-57600HIGH7.5Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers t...
CVE-2026-57599MEDIUM6.6There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the d...
CVE-2026-4773HIGH8.1Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA allows Authenticati...
CVE-2026-44192MEDIUM6.6A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as path traver...
CVE-2026-44190HIGH7.8A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) a...
CVE-2026-44189HIGH7.8A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injec...
CVE-2026-44187LOW3.3A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with ...
CVE-2026-16551MEDIUM6.9Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB module) allows Excessive Allocation. This issue affe...
CVE-2026-16544MEDIUM6.5A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are ...
CVE-2026-16473MEDIUM4.3A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted aud...
CVE-2026-14551HIGH8.8The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are v...
CVE-2026-63264MEDIUM5.3Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3 - The Joomla extension JoomShopping is vuln...
CVE-2026-2406MEDIUM6.5Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industr...
CVE-2026-15787MEDIUM6.4The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu ...
CVE-2026-63048CRITICAL9.4Joomla Extension - joomlack.fr - Improper access control in Page Builder CK 1.0.0-3.1.2, 3.4.0-3.4.11, 3.5.0-3.6.2 - The...
CVE-2026-63047HIGH7.5Joomla Extension - joomdonation.com - Invoice data exfiltration via incorrect ACL check in Events Booking 5.0.0-5.8.1 - ...
CVE-2026-45820HIGH7.5fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with ...
CVE-2026-3821HIGH8.8Supermicro (SMC) SMASH services contain an Arbitrary code execution issue in X14DBG-DAP and X14DBI. An authorized attack...
CVE-2026-14322MEDIUM5.3The Timetics WordPress plugin before 1.0.57 does not enforce a pending or unpaid status for new bookings created throug...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now