2026 CVE Vulnerabilities
64,858 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-90452 | MEDIUM | 6 | 0.1% | Sep 11, 2026 | Requests from the reverse proxy to the identity-provider service for token discovery, introspection, and credential exch... |
| CVE-2026-90450 | MEDIUM | 5.3 | 0.2% | Sep 11, 2026 | The application's role-authorization lookup defaults to granting access when a request handler's name is not present in ... |
| CVE-2026-90449 | MEDIUM | 6.9 | 0.3% | Sep 11, 2026 | When a particular authentication mode is configured, the reverse proxy forwards requests for a bundled third-party admin... |
| CVE-2026-90446 | MEDIUM | 5.3 | 0.2% | Sep 11, 2026 | An application programming interface endpoint accepts a user-supplied value and interpolates it directly into the path o... |
| CVE-2026-90443 | MEDIUM | 5.3 | 0.3% | Sep 11, 2026 | A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate e... |
| CVE-2026-54258 | MEDIUM | 6.5 | 0.2% | Sep 11, 2026 | ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and... |
| CVE-2026-54248 | MEDIUM | 6.5 | 0.2% | Sep 11, 2026 | Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and... |
| CVE-2026-50018 | MEDIUM | 6.5 | 0.3% | Sep 11, 2026 | Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClie... |
| CVE-2026-49992 | MEDIUM | 6.3 | 0.2% | Sep 11, 2026 | Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain authenticated cross-site request for... |
| CVE-2026-48496 | MEDIUM | 6.2 | 0.2% | Sep 11, 2026 | OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages... |
| CVE-2026-45056 | MEDIUM | 6.9 | 0.2% | Sep 11, 2026 | matrix-sdk-crypto is a no-network-IO implementation of a state machine that handles end-to-end encryption for Matrix cli... |
| CVE-2026-81918 | MEDIUM | 4.8 | 0.3% | Sep 11, 2026 | Concrete CMS below 9.5.3 is vulnerable to Stored XSS via the Date Format field in the Page Attribute Display block. A us... |
| CVE-2026-81917 | MEDIUM | 5.4 | 0.3% | Sep 11, 2026 | Concrete CMS below 9.5.3 does not apply HTML output escaping to the file description and tags fields when rendering the ... |
| CVE-2026-68535 | MEDIUM | 4.3 | 0.4% | Sep 11, 2026 | Concrete CMS Area API's block-create endpoint in versions 9.2.0 to 9.5.2 did not invoke the block type controller's vali... |
| CVE-2026-54165 | MEDIUM | 6.4 | 0.3% | Sep 11, 2026 | Dobase is an open-source, self-hosted workspace with installable tools. Versions prior to 2026.06.03 have a one-click st... |
| CVE-2026-50025 | MEDIUM | 6.9 | 0.2% | Sep 11, 2026 | Mousehole is a background service to update a seedbox IP for MAM and web app to manage it. Prior to version 0.4.05, Mous... |
| CVE-2026-49865 | MEDIUM | 5.3 | 0.3% | Sep 11, 2026 | Kimai is an open-source time tracking application. Versions prior to 2.58.0 contain a server-side request forgery vulner... |
| CVE-2026-49439 | MEDIUM | 4.3 | 0.2% | Sep 11, 2026 | OpenRemote is an open-source internet-of-things platform. Prior to version 1.24.1, the predicted datapoint write endpoin... |
| CVE-2026-48490 | MEDIUM | 6.9 | 0.4% | Sep 11, 2026 | ArduinoCore-avr contains the source code and configuration files of the Arduino AVR Boards platform. A vulnerability in ... |
| CVE-2026-45057 | MEDIUM | 4.9 | 0.2% | Sep 11, 2026 | matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in the `matri... |
| CVE-2026-89332 | MEDIUM | 5.5 | 0.2% | Sep 11, 2026 | Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version... |
| CVE-2026-81916 | MEDIUM | 4.3 | 0.3% | Sep 11, 2026 | Concrete CMS before 9.5.3 evaluated the authorization check for an Express entry submission against the entity of the po... |
| CVE-2026-81915 | MEDIUM | 5.3 | 0.4% | Sep 11, 2026 | Concrete CMS below 9.5.3 does not perform an object-level authorization check when a Page Type was updated. The Types::s... |
| CVE-2026-81913 | MEDIUM | 6.1 | 0.6% | Sep 11, 2026 | Concrete CMS versions 9.5.0 through 9.5.2 are vulnerable to Open Redirect via the rcURL parameter. An attacker can craft... |
| CVE-2026-81912 | MEDIUM | 5.7 | 0.2% | Sep 11, 2026 | Concrete CMS before 9.5.3 is vulnerable to Cross-Site Request Forgery in the Move Multiple Groups feature. The dashboard... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now