2026 CVE Vulnerabilities
64,889 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-82438 | HIGH | 8.1 | — | Sep 14, 2026 | Description Three separate mechanisms allowed a web page on an unrelated origin to read responses that Storm's HTTP com... |
| CVE-2026-82432 | HIGH | 8.1 | — | Sep 14, 2026 | Description Nimbus validated `topology.blobstore.map` against the calling subject at submission time only. The rebalanc... |
| CVE-2026-82430 | HIGH | 7.8 | — | Sep 14, 2026 | Description When launching a Docker or OCI worker, the setuid-root `worker-launcher` first changes ownership of the ent... |
| CVE-2026-82429 | HIGH | 7.8 | — | Sep 14, 2026 | Description The setuid-root `worker-launcher` binary adjusts ownership and permissions of worker directories by walking... |
| CVE-2026-82428 | HIGH | 8.8 | — | Sep 14, 2026 | Description Dependency artifacts uploaded with `storm jar --artifacts` were stored under a blob key derived only from t... |
| CVE-2026-82427 | HIGH | 7.8 | — | Sep 14, 2026 | Description A topology's `topology.blobstore.map` lets the submitter choose a local name for each blob that the supervi... |
| CVE-2026-7848 | HIGH | 8.6 | 0.3% | Sep 14, 2026 | Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the "hookActionObjectProdu... |
| CVE-2026-59570 | HIGH | 7.5 | 0.1% | Sep 14, 2026 | On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user ... |
| CVE-2026-59569 | HIGH | 8.1 | 0.1% | Sep 14, 2026 | An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to pot... |
| CVE-2026-57130 | HIGH | 8.1 | 0.3% | Sep 14, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, src/praisonai-agents/praisonaiagents/tools/ema... |
| CVE-2026-57129 | HIGH | 7.5 | — | Sep 14, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, MentionsParser._process_file_mention accepts f... |
| CVE-2026-57126 | HIGH | 8.5 | 0.4% | Sep 14, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, SpiderTools._validate_url calls _host_is_block... |
| CVE-2026-25687 | HIGH | 8.1 | 0.2% | Sep 14, 2026 | A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corrupti... |
| CVE-2026-15600 | HIGH | 8.6 | 0.2% | Sep 14, 2026 | Alior Bank PrestaShop module "raty" for commercial partners is vulnerable to SQL Injection in the toggleCategoryPromotio... |
| CVE-2026-90949 | HIGH | 7.8 | 0.2% | Sep 14, 2026 | A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When processing a compressed selection channel, a heap-base... |
| CVE-2026-90948 | HIGH | 7.8 | 0.2% | Sep 14, 2026 | A flaw was found in GIMP's ICO file loader. When processing an ICO file containing an embedded PNG image, an integer ove... |
| CVE-2026-90787 | HIGH | 7.3 | — | Sep 14, 2026 | A vulnerability was identified in Soarkey StudentManagement up to e08f7f1d5015af407aa4cca0ada3dea189b4937e. Affected is ... |
| CVE-2026-73236 | HIGH | 7.5 | — | Sep 14, 2026 | Incorrect Authorization vulnerability in Apache Syncope. Delegated administration security checks are based on Realm ... |
| CVE-2026-73195 | HIGH | 7.3 | — | Sep 14, 2026 | Improper Encoding or Escaping of Output vulnerability in Apache Syncope. Authenticated users can store a spreadsheet ... |
| CVE-2026-90938 | HIGH | 8.6 | 0.3% | Sep 14, 2026 | LangBot's plugin runtime (pip package langbot_plugin) through 0.4.17 starts a debug WebSocket server on 0.0.0.0:5401 (/p... |
| CVE-2026-90933 | HIGH | 7.1 | 0.2% | Sep 14, 2026 | laradashboard through 1.2.2 contains a missing authorization vulnerability in the Local License API endpoints that allow... |
| CVE-2026-90932 | HIGH | 7.2 | 0.5% | Sep 14, 2026 | LaraDashboard versions 0.9.2 through 1.2.2 contain a path traversal vulnerability in the core-upgrade backup handling. C... |
| CVE-2026-90929 | HIGH | 8.1 | 0.4% | Sep 14, 2026 | File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect authorization flaw in the direct-upload endpoint (res... |
| CVE-2026-90715 | HIGH | 7.3 | — | Sep 14, 2026 | A security vulnerability has been detected in marcobambini Gravity up to 0.9.7. This affects an unknown function of the ... |
| CVE-2026-78336 | HIGH | 7.5 | — | Sep 14, 2026 | Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query f... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now