2026 CVE Vulnerabilities

56,974 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-30623CRITICAL9.8LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application...
CVE-2026-30618CRITICAL9.8xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution...
CVE-2026-26719MEDIUM6.1Cross Site Scripting vulnerability in xxl-job-admin v.3.0.0 allows a remote attacker to execute arbitrary code via a cra...
CVE-2026-26718CRITICAL9.1A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an att...
CVE-2026-15921LOW3.1Node Version Manager (nvm) is a POSIX-compliant shell function for managing multiple node.js versions. In versions 0.32....
CVE-2026-62361MEDIUM5.5listmonk is a standalone, self-hosted, newsletter and mailing list manager. Prior to 6.2.0, listmonk’s GET /api/subscrib...
CVE-2026-62312HIGH8.89Router is an AI router & token saver. Prior to 0.5.2, 9Router allows a remote authenticated attacker to achieve arbitra...
CVE-2026-59950HIGH8.1The MCP Python SDK, called mcp on PyPI, is a Python implementation of the Model Context Protocol (MCP). Prior to 1.28.1,...
CVE-2026-56679HIGH8.79Router is an AI router & token saver. Prior to 0.5.4, the PATCH /api/settings endpoint writes the entire request body t...
CVE-2026-56678MEDIUM6.49Router is an AI router & token saver. Prior to 0.5.6, the Kiro API-key validation endpoint POST /api/oauth/kiro/api-key...
CVE-2026-55608MEDIUM5.4n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior...
CVE-2026-55410MEDIUM6.7NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t...
CVE-2026-55399MEDIUM4.3CVE-2026-55399 is a resource exhaustion vulnerability in the Secure Access publisher prior to 14.55. Attackers with vali...
CVE-2026-55398LOW3.7CVE-2026-55398 is a memory management vulnerability in Secure Access clients and servers prior to 14.55. Attackers with ...
CVE-2026-54052CRITICAL9.9n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior...
CVE-2026-52888MEDIUM6.8NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. In 2.0....
CVE-2026-52887CRITICAL10NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior t...
CVE-2026-51380CRITICAL9.8Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of S...
CVE-2026-49353HIGH7.59Router is an AI router & token saver. In 0.4.45 and earlier, 9Router's src/dashboardGuard.js local-only access gate use...
CVE-2026-49352CRITICAL9.89Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-...
CVE-2026-46339CRITICAL109Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/...
CVE-2026-38753MEDIUM4.9A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a Denial of Serv...
CVE-2026-33684MEDIUM5.3WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded ...
CVE-2026-33445MEDIUM5.9CVE-2026-33445 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with an intimate ...
CVE-2026-33444LOW3.7CVE-2026-33444 is a memory management vulnerability in Secure Access servers prior to 14.55. Attackers with intimate kno...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now