2026 CVE Vulnerabilities
64,868 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-91930 | HIGH | 7.5 | 0.4% | Sep 15, 2026 | Flowise before 3.1.4 fails to scope enterprise organization and workspace membership APIs to the caller's tenant, allowi... |
| CVE-2026-91929 | HIGH | 7.1 | 0.3% | Sep 15, 2026 | Flowise versions before 3.1.4 contain cross-tenant authorization gaps in Enterprise endpoints that fail to verify resour... |
| CVE-2026-91848 | HIGH | 7.3 | 0.5% | Sep 15, 2026 | A vulnerability was identified in WuzhiCMS up to 4.1.0. Affected by this issue is the function article::getDataOfJson of... |
| CVE-2026-88619 | HIGH | 8.1 | 0.3% | Sep 15, 2026 | 1024-lab SmartAdmin v3.30.0 contains a missing authorization vulnerability in the scheduled-job management module. The A... |
| CVE-2026-87792 | HIGH | 8.7 | 0.4% | Sep 15, 2026 | The "Design Scuole Italia" WordPress theme is affected by multiple Authorization Bypass vulnerabilities in the dsi_pdf_g... |
| CVE-2026-87791 | HIGH | 8.7 | 0.4% | Sep 15, 2026 | A path traversal vulnerability exists in the reserved_file_check function of the functions.php file in the WordPress Des... |
| CVE-2026-85013 | HIGH | 7.3 | 0.2% | Sep 15, 2026 | A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named ... |
| CVE-2026-65831 | HIGH | 7.7 | — | Sep 15, 2026 | ArcadeDB is a Multi-Model DBMS. Prior to 26.7.1, a reader-role user can submit POST /api/v1/command/{database} with lang... |
| CVE-2026-59973 | HIGH | 8.5 | 0.4% | Sep 15, 2026 | FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). From mcp-from-openapi 2.3.0 until 2.5.0 a... |
| CVE-2026-59965 | HIGH | 7.1 | 0.3% | Sep 15, 2026 | Payload Plugins is a collection of plugins designed to enhance Payload CMS. In 0.7.0, @jhb.software/payload-alt-text-plu... |
| CVE-2026-55887 | HIGH | 8.7 | — | Sep 15, 2026 | MCP Gateway allows easy and secure running and deployment of MCP servers. From 0.21.0 until 0.42.2, Docker MCP Gateway Y... |
| CVE-2026-55864 | HIGH | 7.8 | 0.6% | Sep 15, 2026 | GeoNetwork is a catalog application to manage spatially referenced resources. Prior to 4.2.17 and 4.4.12, POST /api/tool... |
| CVE-2026-54077 | HIGH | 7.1 | — | Sep 15, 2026 | ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the IMPORT DATABASE statement in engine/src/main/java/com/arcadedb/quer... |
| CVE-2026-54076 | HIGH | 8.1 | — | Sep 15, 2026 | ArcadeDB is a Multi-Model DBMS. Prior to 26.6.1, the fix for CVE-2026-44221 added an UPDATE_SCHEMA authorization check o... |
| CVE-2026-19407 | HIGH | 7.7 | 0.5% | Sep 15, 2026 | Bucket Squatting in Google Cloud Gemini Enterprise Agent Platform SDK for Python versions prior to 1.166.1 allows an att... |
| CVE-2026-90650 | HIGH | 7.2 | 0.2% | Sep 15, 2026 | The MotoPress Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Stripe Webhook eve... |
| CVE-2026-89025 | HIGH | 7.5 | 0.8% | Sep 15, 2026 | Hirschmann HiOS Switch Platform devices contain a denial-of-service vulnerability in the integrated web server due to mi... |
| CVE-2026-88616 | HIGH | 8.8 | 0.6% | Sep 15, 2026 | An issue in RuoYi-Vue-Plus 6.0.0 allows a remote attacker to execute arbitrary code via the FlwTaskController.java compo... |
| CVE-2026-79551 | HIGH | 7.5 | 0.3% | Sep 15, 2026 | Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to contain a hardcoded cryptographic key. |
| CVE-2026-79425 | HIGH | 8.1 | 0.3% | Sep 15, 2026 | An authenticated Server-Side Request Forgery (SSRF) in the /adminapi/file/online_upload component of CRMEB v6.0.0 allows... |
| CVE-2026-57586 | HIGH | 8.6 | — | Sep 15, 2026 | CodeRAG is a lightweight semantic code search and distillation utility for AI coding agents. Prior to 1.3.1, the default... |
| CVE-2026-55178 | HIGH | 7.5 | 0.4% | Sep 15, 2026 | GeoLens is a self-hosted geospatial data catalog with semantic search, OGC and STAC APIs, and a map builder. Prior to 1.... |
| CVE-2026-54167 | HIGH | 8.2 | — | Sep 15, 2026 | Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8... |
| CVE-2026-53966 | HIGH | 7.1 | — | Sep 15, 2026 | XWiki Platform is a generic wiki platform. From 13.4-rc-1 until 16.10.17, 17.4.10, 17.10.4, and 18.1.0-rc-1, the Live Da... |
| CVE-2026-53957 | HIGH | 7.7 | 0.2% | Sep 15, 2026 | Contentful MCP Server is a Model Context Protocol server for the Contentful Management API. Prior to @contentful/mcp-ser... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now