2026 CVE Vulnerabilities
64,868 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-19780 | HIGH | 8.8 | 1.0% | Sep 15, 2026 | Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbi... |
| CVE-2026-18111 | HIGH | 8.5 | 0.3% | Sep 15, 2026 | Concrete CMS 9 before 9.5.3 was vulnerable to stored cross-site scripting (XSS) in the Feature, Feature Link, Hero Image... |
| CVE-2026-18110 | HIGH | 7.5 | 0.3% | Sep 15, 2026 | Concrete CMS 9 (9.0.0 through 9.5.2) does not perform an authorization check on the user selector autocomplete endpoint ... |
| CVE-2026-91990 | HIGH | 7.5 | — | Sep 15, 2026 | Tornado before 6.5.8 contains a memory amplification vulnerability in parse_multipart_form_data that splits multipart da... |
| CVE-2026-91989 | HIGH | 7.5 | 1.3% | Sep 15, 2026 | atomic-agents-stack before 1.1.0 contains a path traversal vulnerability in the dashboard HTTP server that allows remote... |
| CVE-2026-91988 | HIGH | 8.1 | 0.3% | Sep 15, 2026 | atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes in the HTTP MCP server-registry backend factory, allowin... |
| CVE-2026-91985 | HIGH | 7.5 | 0.4% | Sep 15, 2026 | Vikunja before 2.6.0 fails to properly restrict access to the link-share hash field in single-share read endpoints, allo... |
| CVE-2026-91973 | HIGH | 7.5 | 0.6% | Sep 15, 2026 | Vikunja before 2.6.0 contains an authentication bypass vulnerability in CalDAV BasicAuth endpoints that lack rate limiti... |
| CVE-2026-91972 | HIGH | 7.5 | 0.5% | Sep 15, 2026 | Vikunja versions before 2.6.0 fail to apply rate limiting to /api/v2 public authentication endpoints including login, re... |
| CVE-2026-91965 | HIGH | 7.5 | 0.4% | Sep 15, 2026 | WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/cale... |
| CVE-2026-91964 | HIGH | 8.8 | 0.6% | Sep 15, 2026 | FreeRDP versions before 3.31.0 contain a heap-based buffer overflow in nego_send_negotiation_request when processing Ser... |
| CVE-2026-91955 | HIGH | 7.5 | 0.5% | Sep 15, 2026 | FreeRDP before 3.31.0 fails to validate client-supplied DesktopWidth and DesktopHeight values during GCC negotiation, al... |
| CVE-2026-91948 | HIGH | 7.5 | 0.6% | Sep 15, 2026 | FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in server-side static virtual channel handli... |
| CVE-2026-91947 | HIGH | 7.5 | 0.3% | Sep 15, 2026 | FreeRDP server versions before 3.31.0 contain a use-after-free vulnerability in the DRDYNVC parser that dereferences a c... |
| CVE-2026-91943 | HIGH | 7.7 | 0.3% | Sep 15, 2026 | Crawl4AI before 0.9.3 contains a server-side request forgery vulnerability in PDFContentScrapingStrategy where _get_pdf_... |
| CVE-2026-91941 | HIGH | 7.5 | 0.4% | Sep 15, 2026 | Crawl4AI before 0.9.3 contains an uncontrolled resource consumption vulnerability in PDFContentScrapingStrategy that all... |
| CVE-2026-91940 | HIGH | 7.5 | 0.4% | Sep 15, 2026 | crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_unt... |
| CVE-2026-91938 | HIGH | 7.1 | 0.3% | Sep 15, 2026 | Flowise versions before 3.1.4 contain a server-side request forgery vulnerability in Cheerio, Playwright, and Puppeteer ... |
| CVE-2026-91937 | HIGH | 7.5 | 0.3% | Sep 15, 2026 | Flowise before 3.1.4 fails to sanitize the overrideConfig.sessionId parameter before using it in MongoDB queries within ... |
| CVE-2026-91935 | HIGH | 8.3 | 0.3% | Sep 15, 2026 | Flowise before 3.1.4 fails to validate baseURL parameters in chat-model nodes, allowing authenticated users to redirect ... |
| CVE-2026-91934 | HIGH | 8.8 | 0.7% | Sep 15, 2026 | Flowise versions before 3.1.4 fail to validate file paths in the SQL Database Chain node when connecting to SQLite datab... |
| CVE-2026-91933 | HIGH | 7.1 | 0.3% | Sep 15, 2026 | Flowise before 3.1.4 fails to enforce workspace-level authorization checks in openai-realtime endpoints, allowing authen... |
| CVE-2026-91932 | HIGH | 8.5 | 0.8% | Sep 15, 2026 | Flowise before 3.1.4 contains a validation bypass vulnerability in MCP server configuration allowing authenticated attac... |
| CVE-2026-91931 | HIGH | 8.5 | 0.6% | Sep 15, 2026 | Flowise before 3.1.4 contains a remote code execution vulnerability in the Custom MCP node that allows authenticated att... |
| CVE-2026-91930 | HIGH | 7.5 | 0.4% | Sep 15, 2026 | Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now