2026 CVE Vulnerabilities
66,317 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-61823 | HIGH | 7.3 | 0.2% | Sep 24, 2026 | code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before... |
| CVE-2026-57440 | HIGH | 7.5 | 0.3% | Sep 24, 2026 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for em... |
| CVE-2026-56792 | MEDIUM | 4.4 | — | Sep 24, 2026 | Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low priv... |
| CVE-2026-52853 | MEDIUM | 5.2 | — | Sep 24, 2026 | Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace ADMIN ... |
| CVE-2026-52850 | MEDIUM | 4.3 | — | Sep 24, 2026 | Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace member... |
| CVE-2026-48073 | MEDIUM | 4.3 | — | Sep 24, 2026 | Docmost is open-source collaborative wiki and documentation software. From 0.70.0 until 0.80.1, a low-privileged authent... |
| CVE-2026-48072 | MEDIUM | 5.3 | — | Sep 24, 2026 | Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, the public avatar and logo image ... |
| CVE-2026-48070 | HIGH | 7.1 | — | Sep 24, 2026 | Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, authenticated users can store att... |
| CVE-2026-13249 | CRITICAL | 9.8 | — | Sep 24, 2026 | An unauthenticated Remote Code Execution via Arbitrary File Upload vulnerability in the web management interface in Hone... |
| CVE-2026-13248 | HIGH | 8.8 | — | Sep 24, 2026 | An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerabil... |
| CVE-2026-13016 | CRITICAL | 9.3 | — | Sep 24, 2026 | ServiceNow has remediated a SQL injection vulnerability that was identified in the ServiceNow AI Platform. This vulnerab... |
| CVE-2026-97233 | LOW | 3.5 | — | Sep 24, 2026 | A vulnerability was identified in volotat Anagnorisis up to 0.4.11. Affected by this issue is the function html of the f... |
| CVE-2026-97232 | MEDIUM | 6.3 | — | Sep 24, 2026 | A vulnerability was determined in volotat Anagnorisis up to 0.4.2. Affected by this vulnerability is the function get_fi... |
| CVE-2026-95985 | HIGH | 8.8 | — | Sep 24, 2026 | The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject craft... |
| CVE-2026-93405 | MEDIUM | 6.1 | 0.2% | Sep 24, 2026 | Mailspring is a fast, cross-platform, open-source email client. Prior to 1.17.0, attachment quick preview converts Markd... |
| CVE-2026-91121 | MEDIUM | 5 | — | Sep 24, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, attacker-controlle... |
| CVE-2026-91120 | MEDIUM | 5.4 | — | Sep 24, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, provider-controlle... |
| CVE-2026-91119 | MEDIUM | 6.4 | — | Sep 24, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the topic small-ac... |
| CVE-2026-85057 | HIGH | 8.7 | — | Sep 24, 2026 | ZITADEL is an open source identity management platform. From 3.0.0 until 3.4.13 and 4.16.1, ZITADEL Actions V1 enables t... |
| CVE-2026-85056 | HIGH | 8.2 | — | Sep 24, 2026 | ZITADEL is an open source identity management platform. From 4.0.0 until 4.16.1, ZITADEL Login V2 creates a browser sess... |
| CVE-2026-81508 | MEDIUM | 4.3 | — | Sep 24, 2026 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.5, 6.0.1, and 6.1, the BlueDroid A2DP si... |
| CVE-2026-71540 | HIGH | 7.5 | 0.4% | Sep 24, 2026 | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. F... |
| CVE-2026-63645 | HIGH | 7.5 | 0.3% | Sep 24, 2026 | OpenObserve is a cloud-native observability platform. Prior to 0.90.3, OpenObserve registers the /config/runtime endpoin... |
| CVE-2026-61816 | HIGH | 7.5 | 0.4% | Sep 24, 2026 | zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading mess... |
| CVE-2026-61815 | HIGH | 7.2 | 0.2% | Sep 24, 2026 | zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading mess... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now