2026 CVE Vulnerabilities
64,868 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-88898 | MEDIUM | 6.5 | — | Sep 10, 2026 | AppFlowy-Cloud versions 0.7.2 through 0.9.64 fail to authorize callers against the workspace in the bulk publish endpoin... |
| CVE-2026-88897 | MEDIUM | 5.9 | 0.3% | Sep 10, 2026 | Flextype CMS through 1.0.0-alpha.3 accepts API authentication credentials through URL query string parameters in REST AP... |
| CVE-2026-88006 | MEDIUM | 6.5 | 0.2% | Sep 10, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.1, Open WebU... |
| CVE-2026-88005 | MEDIUM | 6.5 | 0.2% | Sep 10, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.9.0, Open WebUI... |
| CVE-2026-85310 | MEDIUM | 6.5 | — | Sep 10, 2026 | import_contacts Path Traversal in Groundhogg <= 4.7.1 versions. |
| CVE-2026-81793 | MEDIUM | 6.5 | 0.2% | Sep 10, 2026 | Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions. |
| CVE-2026-81791 | MEDIUM | 6.5 | — | Sep 10, 2026 | Subscriber Cross Site Scripting (XSS) in EventON <= 2.5.7 versions. |
| CVE-2026-81788 | MEDIUM | 6.3 | — | Sep 10, 2026 | Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions. |
| CVE-2026-81787 | MEDIUM | 6.5 | — | Sep 10, 2026 | Unauthenticated Broken Authentication in IMPress for IDX Broker <= 3.3.0 versions. |
| CVE-2026-81785 | MEDIUM | 6.5 | — | Sep 10, 2026 | Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions. |
| CVE-2026-81782 | MEDIUM | 6.5 | — | Sep 10, 2026 | Subscriber Cross Site Scripting (XSS) in WP Docs <= 2.3.1 versions. |
| CVE-2026-81275 | MEDIUM | 6.5 | 0.4% | Sep 10, 2026 | Subscriber Arbitrary File Download in Youzify <= 1.3.7 versions. |
| CVE-2026-78536 | MEDIUM | 6.5 | — | Sep 10, 2026 | Unauthenticated Broken Access Control in Robokassa payment gateway for Woocommerce <= 1.8.9 versions. |
| CVE-2026-66674 | MEDIUM | 5.6 | — | Sep 10, 2026 | Unauthenticated Bypass Vulnerability in Simple Cloudflare Turnstile <= 1.42.1 versions. |
| CVE-2026-66632 | MEDIUM | 6.5 | — | Sep 10, 2026 | Unauthenticated Content Injection in Simple Cloudflare Turnstile <= 1.42.1 versions. |
| CVE-2026-15461 | MEDIUM | 5.3 | — | Sep 10, 2026 | The Sierra Wireless HL78xx modem GNSS driver (drivers/modem/hl78xx/, later drivers/modem/vendor_standalone/hl78xx/) embe... |
| CVE-2026-88921 | MEDIUM | 5.1 | — | Sep 10, 2026 | MISP contains an HTML injection vulnerability in the MISPElementHTMLFormatterTool component, which is responsible for re... |
| CVE-2026-88896 | MEDIUM | 5.3 | 0.3% | Sep 10, 2026 | EspoCRM before 10.0.4 is vulnerable to server-side request forgery. HostCheck::ipAddressIsNotInternal(), which validates... |
| CVE-2026-88894 | MEDIUM | 5.4 | — | Sep 10, 2026 | Snipe-IT's predefined kit checkout path does not enforce Full Multiple Company Support (FMCS) tenant isolation on the ch... |
| CVE-2026-88892 | MEDIUM | 5 | — | Sep 10, 2026 | OpenPanel is an analytics platform. In all versions (no patched release available at time of publication), the data impo... |
| CVE-2026-88884 | MEDIUM | 5.8 | — | Sep 10, 2026 | Renovate is a dependency update automation tool. In versions before 44.3.1 (and Mend Renovate CE/EE images before 15.4.0... |
| CVE-2026-88878 | MEDIUM | 5.3 | 0.3% | Sep 10, 2026 | Traefik is an HTTP reverse proxy and load balancer. In versions >= v2.8.2 through <= v2.11.55 and >= v3.0.0 through <= v... |
| CVE-2026-88875 | MEDIUM | 4.3 | 0.2% | Sep 10, 2026 | AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) incompletely sanitizes sensitive u... |
| CVE-2026-88871 | MEDIUM | 4.3 | 0.1% | Sep 10, 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) contains a cross-site request f... |
| CVE-2026-88860 | MEDIUM | 6.3 | 0.2% | Sep 10, 2026 | Capgo fails to clean up channel permission overrides when a user's last organization role binding is deleted, leaving st... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now