2026 CVE Vulnerabilities
64,704 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-101033 | MEDIUM | 4.3 | — | Sep 27, 2026 | KitchenOwl through 0.7.10 fails to verify that category IDs belong to the caller's household in expense and item operati... |
| CVE-2026-100869 | MEDIUM | 5.9 | — | Sep 27, 2026 | Sylius versions before 2.1.16 and 2.2.9 fail to restrict payment request actions in the Shop API endpoint, allowing cust... |
| CVE-2026-100868 | MEDIUM | 6.3 | — | Sep 27, 2026 | Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in si... |
| CVE-2026-97165 | MEDIUM | 5.3 | — | Sep 27, 2026 | Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0 - The “return” par... |
| CVE-2026-100749 | MEDIUM | 5.1 | — | Sep 27, 2026 | Joomla Extension - svenbluege.de - CSRF in backend cleanup actions in Event Gallery extension < 6.5.0 - Only orphaned fi... |
| CVE-2026-100748 | MEDIUM | 6.9 | — | Sep 27, 2026 | Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.0 |
| CVE-2026-100747 | MEDIUM | 5.1 | — | Sep 27, 2026 | Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF toke... |
| CVE-2026-93304 | MEDIUM | 6.3 | — | Sep 27, 2026 | A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. No master secret has... |
| CVE-2026-89135 | MEDIUM | 6.3 | — | Sep 27, 2026 | A failed X509_verify_cert call permanently plants an unverified attacker CA in the shared CertManager, bypassing certifi... |
| CVE-2026-89134 | MEDIUM | 6.3 | — | Sep 27, 2026 | A certificate with no dNSName SAN but another SAN type present (e.g. registeredID or iPAddress) bypassed the Subject CN ... |
| CVE-2026-89133 | MEDIUM | 6.3 | — | Sep 27, 2026 | wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509 certificate validation logic where it fails to properly e... |
| CVE-2026-100863 | MEDIUM | 5 | — | Sep 27, 2026 | Heym versions 0.0.90 and earlier contain two server-side request forgery (SSRF) egress gaps, both remediated in app/serv... |
| CVE-2026-100862 | MEDIUM | 4.9 | — | Sep 27, 2026 | heym, a workflow automation platform, stores and returns multiple capability secrets in plaintext in versions prior to 0... |
| CVE-2026-100861 | MEDIUM | 5 | — | Sep 27, 2026 | heym before 0.0.105 fails to apply egress guards to integration services that use credential-supplied base URLs, allowin... |
| CVE-2026-100860 | MEDIUM | 5.5 | — | Sep 27, 2026 | heym before 0.0.105 does not act on the result of the credential authorization lookup in the Redis workflow node (backen... |
| CVE-2026-100859 | MEDIUM | 6.5 | — | Sep 27, 2026 | Heym before 0.0.106 contains a credential exfiltration vulnerability in the POST /api/credentials/test endpoint that all... |
| CVE-2026-100858 | MEDIUM | 6.8 | — | Sep 27, 2026 | heym before 0.0.109 contains a server-side request forgery vulnerability in the Slack, Discord, and Crawler workflow nod... |
| CVE-2026-100855 | MEDIUM | 6.5 | — | Sep 27, 2026 | AzuraCast before 0.23.6 contains a missing permission check vulnerability in the GET /api/station/{station_id}/file/{id}... |
| CVE-2026-100854 | MEDIUM | 6.3 | — | Sep 27, 2026 | AzuraCast before 0.23.6 lacks RequireInternalConnection middleware on the Liquidsoap API endpoint and incorrectly derive... |
| CVE-2026-100853 | MEDIUM | 5.9 | — | Sep 27, 2026 | In AzuraCast before 0.23.8, the public On-Demand download endpoint fails to verify playlist-level access controls, allow... |
| CVE-2026-100836 | MEDIUM | 4.3 | — | Sep 27, 2026 | Contrast through 1.20.0 contains a panic vulnerability in the transit-engine endpoint's ciphertextContainer.UnmarshalJSO... |
| CVE-2026-100834 | MEDIUM | 5.9 | — | Sep 27, 2026 | http4k's Digest authentication module (org.http4k:http4k-security-digest) before versions 6.48.0.0, 5.42.0.0 and 4.51.0.... |
| CVE-2026-100745 | MEDIUM | 6.3 | — | Sep 27, 2026 | A vulnerability has been found in Edimax BR-6428nC 1.16. The impacted element is an unknown function of the file /goform... |
| CVE-2026-100725 | MEDIUM | 6.5 | — | Sep 27, 2026 | http4k (Maven artifact org.http4k:http4k-core) before 6.48.0.0, 5.42.0.0, and 4.51.0.0 ships a BasicCookieStorage (clien... |
| CVE-2026-100724 | MEDIUM | 5.4 | — | Sep 27, 2026 | http4k (Maven package org.http4k:http4k-core) before 6.49.0.0, 5.42.0.0 and 4.51.0.0 uses substring (Contains) matching ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now