2026 CVE Vulnerabilities
56,974 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30623 | CRITICAL | 9.8 | 0.3% | Jul 15, 2026 | LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application... |
| CVE-2026-30618 | CRITICAL | 9.8 | 0.6% | Jul 15, 2026 | xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution... |
| CVE-2026-26719 | MEDIUM | 6.1 | 0.4% | Jul 15, 2026 | Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote attacker to execute arbitrary code via a cra... |
| CVE-2026-26718 | CRITICAL | 9.1 | 0.3% | Jul 15, 2026 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an att... |
| CVE-2026-15921 | LOW | 3.1 | 0.2% | Jul 15, 2026 | Node Version Manager (nvm) is a POSIX-compliant shell function for managing multiple node.js versions. In versions 0.32.... |
| CVE-2026-62361 | MEDIUM | 5.5 | 0.2% | Jul 15, 2026 | listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to 6.2.0, listmonk’s GET /api/subscrib... |
| CVE-2026-62312 | HIGH | 8.8 | 0.7% | Jul 15, 2026 | 9Router is an AI router & token saver. Prior to 0.5.2, 9Router allows a remote authenticated attacker to achieve arbitra... |
| CVE-2026-59950 | HIGH | 8.1 | 0.2% | Jul 15, 2026 | The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1,... |
| CVE-2026-56679 | HIGH | 8.7 | 0.3% | Jul 15, 2026 | 9Router is an AI router & token saver. Prior to 0.5.4, the PATCH /api/settings endpoint writes the entire request body t... |
| CVE-2026-56678 | MEDIUM | 6.4 | 0.2% | Jul 15, 2026 | 9Router is an AI router & token saver. Prior to 0.5.6, the Kiro API-key validation endpoint POST /api/oauth/kiro/api-key... |
| CVE-2026-55608 | MEDIUM | 5.4 | 0.3% | Jul 15, 2026 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior... |
| CVE-2026-55410 | MEDIUM | 6.7 | 0.4% | Jul 15, 2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t... |
| CVE-2026-55399 | MEDIUM | 4.3 | 0.2% | Jul 15, 2026 | CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with vali... |
| CVE-2026-55398 | LOW | 3.7 | 0.3% | Jul 15, 2026 | CVE-2026-55398 is a memory management vulnerability in Secure Access clients and servers prior to 14.55. Attackers with ... |
| CVE-2026-54052 | CRITICAL | 9.9 | 0.4% | Jul 15, 2026 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior... |
| CVE-2026-52888 | MEDIUM | 6.8 | 0.3% | Jul 15, 2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0.... |
| CVE-2026-52887 | CRITICAL | 10 | 0.6% | Jul 15, 2026 | NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t... |
| CVE-2026-51380 | CRITICAL | 9.8 | 0.2% | Jul 15, 2026 | Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of S... |
| CVE-2026-49353 | HIGH | 7.5 | 0.4% | Jul 15, 2026 | 9Router is an AI router & token saver. In 0.4.45 and earlier, 9Router's src/dashboardGuard.js local-only access gate use... |
| CVE-2026-49352 | CRITICAL | 9.8 | 0.6% | Jul 15, 2026 | 9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-... |
| CVE-2026-46339 | CRITICAL | 10 | 4.6% | Jul 15, 2026 | 9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/... |
| CVE-2026-38753 | MEDIUM | 4.9 | 0.3% | Jul 15, 2026 | A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Serv... |
| CVE-2026-33684 | MEDIUM | 5.3 | 0.3% | Jul 15, 2026 | WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded ... |
| CVE-2026-33445 | MEDIUM | 5.9 | 0.3% | Jul 15, 2026 | CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate ... |
| CVE-2026-33444 | LOW | 3.7 | 0.3% | Jul 15, 2026 | CVE-2026-33444 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with intimate kno... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now