2026 CVE Vulnerabilities

56,949 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-13445HIGH8.1IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read an...
CVE-2026-8861MEDIUM5.3IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error messag...
CVE-2026-8859CRITICAL9.9IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations ...
CVE-2026-8635CRITICAL9.9IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipul...
CVE-2026-8505CRITICAL9.8IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthentica...
CVE-2026-8481CRITICAL9.9IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API ...
CVE-2026-8476CRITICAL9.9IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching m...
CVE-2026-8056HIGH8.8IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API...
CVE-2026-7872HIGH8.1IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing...
CVE-2026-7771MEDIUM5.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a specially crafted stat...
CVE-2026-7755HIGH8.8IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcemen...
CVE-2026-7754MEDIUM6.5IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure defa...
CVE-2026-7667HIGH8.8IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacke...
CVE-2026-7364MEDIUM6.1IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Ident...
CVE-2026-63030CRITICAL9.8WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which...
CVE-2026-60137MEDIUM5.9WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in p...
CVE-2026-55254MEDIUM6.5NCalc is a fast, lightweight expression evaluator for .NET. Prior to 6.1.1, the factorial operator implementation in src...
CVE-2026-54465HIGH7.5websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-driver is used to im...
CVE-2026-54464MEDIUM6.3### Impact If this library is used in tandem with the `permessage-deflate` extension, a WebSocket server or client can ...
CVE-2026-54463HIGH7.5websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions of the WebSocket pro...
CVE-2026-54171MEDIUM6.5Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip add...
CVE-2026-52199CRITICAL9.1An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/...
CVE-2026-51833HIGH7.5Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can ...
CVE-2026-50289HIGH8.8systeminformation is a System and OS information library for node.js. Prior to 5.31.7, networkInterfaces() on Linux is v...
CVE-2026-50197HIGH7.8Skipper is an HTTP router and reverse proxy for service composition. Prior to 0.26.10, zalando/skipper's OpenPolicyAgent...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now