2026 CVE Vulnerabilities
64,889 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53659 | HIGH | 7.5 | — | Sep 14, 2026 | http4k is a functional toolkit for Kotlin HTTP applications. Prior to 4.51.0.0, 5.42.0.0, and 6.49.0.0, ServerFilters.GZ... |
| CVE-2026-50276 | HIGH | 7.5 | 0.8% | Sep 14, 2026 | dd-trace-rb is Datadog's client library for Ruby. Prior to 2.32.0, W3C baggage extraction does not enforce DD_TRACE_BAGG... |
| CVE-2026-50270 | HIGH | 7.5 | — | Sep 14, 2026 | dd-trace-java is a Datadog APM client for Java. Prior to 1.62.0, W3C baggage extraction does not enforce DD_TRACE_BAGGAG... |
| CVE-2026-49250 | HIGH | 8.7 | — | Sep 14, 2026 | Conform, a type-safe form validation library, allows the parsing of nested objects in the form of object.property. From ... |
| CVE-2026-34151 | HIGH | 8.2 | — | Sep 14, 2026 | XWiki Platform is a generic wiki platform. Prior to 17.10.5 and 18.2.0, the /skin/ action in com.xpn.xwiki.web.SkinActio... |
| CVE-2026-19499 | HIGH | 7.7 | 0.4% | Sep 14, 2026 | Calling strfmon and strfmon_l in the GNU C Library version 2.38 to 2.44 can write past the end of the caller-supplied ou... |
| CVE-2026-84445 | HIGH | 8.7 | 0.7% | Sep 14, 2026 | gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and 1.83.2, servers created with xds.NewGRPCServer() ... |
| CVE-2026-76442 | HIGH | 7.5 | 0.3% | Sep 14, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisc... |
| CVE-2026-61701 | HIGH | 8.8 | — | Sep 14, 2026 | Laravel MagicLink creates links for authentication without a password or for accessing private content. From 2.0.0 until... |
| CVE-2026-59960 | HIGH | 7.5 | — | Sep 14, 2026 | Argos JavaScript provides official Argos SDKs for JavaScript. Prior to Argos core package version 6.2.1, attacker-contro... |
| CVE-2026-57579 | HIGH | 7.5 | — | Sep 14, 2026 | Alchemy is an open source content management system engine written in Ruby on Rails. Prior to 7.4.15, 8.0.15, 8.1.14, an... |
| CVE-2026-55451 | HIGH | 8.3 | — | Sep 14, 2026 | gettext-converter provides gettext resource conversion utilities for JavaScript. Prior to 1.3.3, js2i18next() in lib/js2... |
| CVE-2026-55416 | HIGH | 8.8 | 0.6% | Sep 14, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an authenticat... |
| CVE-2026-55072 | HIGH | 8.5 | 0.4% | Sep 14, 2026 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 2026.1.5, an authenticated user with the objec... |
| CVE-2026-54156 | HIGH | 7.5 | — | Sep 14, 2026 | node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the process-global g_alreadyUsedNon... |
| CVE-2026-54155 | HIGH | 7.7 | — | Sep 14, 2026 | node-opcua is an OPC UA implementation for TypeScript and Node.js. Prior to 2.166.0, the UserNameIdentityToken authentic... |
| CVE-2026-90947 | HIGH | 7.8 | 0.1% | Sep 14, 2026 | A flaw was found in GIMP. When processing a specially crafted lighting preset file, the Lighting Effects filter does not... |
| CVE-2026-90943 | HIGH | 8.7 | 0.4% | Sep 14, 2026 | parallax filament-comments through 3.0.0 contains a stored cross-site scripting vulnerability in comment body rendering ... |
| CVE-2026-81301 | HIGH | 8.5 | 0.1% | Sep 14, 2026 | Ekia File Manager 1.2.7 exposes com.ekia.filecontrolmanager.OpenFileProvider as an exported Android ContentProvider with... |
| CVE-2026-57132 | HIGH | 8.2 | 0.3% | Sep 14, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.6.62, setting PRAISONAI_CALL_AUTH to disabled makes verify_token acc... |
| CVE-2026-57122 | HIGH | 8.6 | 0.1% | Sep 14, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.6.59, the WhatsApp and Linear bot webhook handlers verify HMAC signa... |
| CVE-2026-57119 | HIGH | 7.5 | 0.4% | Sep 14, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.6.59, the unauthenticated Jobs API accepts an absolute or traversing... |
| CVE-2026-56839 | HIGH | 7.3 | 0.3% | Sep 14, 2026 | PraisonAI is a multi-agent teams system. Prior to 4.6.59, the CODE_TOOLS wrappers keep _workspace_root as None and pass ... |
| CVE-2026-47701 | HIGH | 7.7 | 0.5% | Sep 14, 2026 | The OpenTelemetry Operator is a Kubernetes Operator for the OpenTelemetry Collector. Prior to 0.152.0, cmd/otel-allocato... |
| CVE-2026-90789 | HIGH | 7.3 | — | Sep 14, 2026 | A weakness has been identified in itsourcecode Leave Management System 1.0. Affected by this issue is some unknown funct... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now