2026 CVE Vulnerabilities
66,316 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-97323 | MEDIUM | 6.3 | — | Sep 24, 2026 | A vulnerability was determined in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This impacts the function getOrigina... |
| CVE-2026-97322 | MEDIUM | 4.3 | — | Sep 24, 2026 | A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This affects an unknown function of the f... |
| CVE-2026-97321 | MEDIUM | 6.3 | — | Sep 24, 2026 | A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The impacted element is the function... |
| CVE-2026-97320 | MEDIUM | 6.3 | 0.2% | Sep 24, 2026 | A flaw has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The affected element is the function AiKnowle... |
| CVE-2026-96749 | HIGH | 8.4 | 0.1% | Sep 24, 2026 | An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may ... |
| CVE-2026-96748 | MEDIUM | 6.5 | — | Sep 24, 2026 | PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separ... |
| CVE-2026-96747 | MEDIUM | 5 | — | Sep 24, 2026 | The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value en... |
| CVE-2026-89325 | HIGH | 7.8 | 0.1% | Sep 24, 2026 | An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, l... |
| CVE-2026-86860 | CRITICAL | 9.3 | — | Sep 24, 2026 | ServiceNow has remediated a missing authorization vulnerability that was identified in the ServiceNow AI Platform. This ... |
| CVE-2026-86859 | HIGH | 8.7 | — | Sep 24, 2026 | ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This... |
| CVE-2026-86858 | HIGH | 8.7 | — | Sep 24, 2026 | ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. T... |
| CVE-2026-86857 | HIGH | 8.4 | — | Sep 24, 2026 | ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This... |
| CVE-2026-85738 | MEDIUM | 6.3 | — | Sep 24, 2026 | TREK is a collaborative travel planner. Prior to 3.4.0, the checkSsrf logic in server/src/utils/ssrfGuard.ts does not re... |
| CVE-2026-82371 | HIGH | 8.5 | — | Sep 24, 2026 | Plaintext exposure of sensitive authentication data in Brocade SANnav discovery service log files enables individuals wi... |
| CVE-2026-82157 | HIGH | 8.3 | — | Sep 24, 2026 | Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an Improper Certificate Validation vulnerabil... |
| CVE-2026-81473 | HIGH | 8.1 | — | Sep 24, 2026 | Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low priv... |
| CVE-2026-81455 | HIGH | 8.6 | — | Sep 24, 2026 | Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function... |
| CVE-2026-77321 | MEDIUM | 4.3 | — | Sep 24, 2026 | TREK is a collaborative travel planner. Prior to 3.3.0, the get_trip_summary tool in server/src/mcp/tools/trips.ts is re... |
| CVE-2026-77320 | MEDIUM | 5.3 | — | Sep 24, 2026 | TREK is a collaborative travel planner. Prior to 3.3.0, getSharedTripData in server/src/services/shareService.ts returns... |
| CVE-2026-77294 | HIGH | 8.1 | — | Sep 24, 2026 | TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlle... |
| CVE-2026-77293 | HIGH | 7.1 | — | Sep 24, 2026 | TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:noteId/files/:fileId... |
| CVE-2026-65827 | MEDIUM | 6.5 | — | Sep 24, 2026 | Docmost is open-source collaborative wiki and documentation software. From 0.21.0 until 0.95.0, any authenticated worksp... |
| CVE-2026-62286 | MEDIUM | 4.3 | 0.3% | Sep 24, 2026 | Dozzle is a realtime log viewer for docker containers. Prior to 10.6.7, streamEvents in internal/web/events.go applies a... |
| CVE-2026-61825 | HIGH | 8.7 | 0.2% | Sep 24, 2026 | code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before... |
| CVE-2026-61823 | HIGH | 7.3 | 0.2% | Sep 24, 2026 | code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now