2026 CVE Vulnerabilities
64,909 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-90601 | HIGH | 7.3 | 0.4% | Sep 13, 2026 | A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_serv... |
| CVE-2026-15891 | HIGH | 7.5 | 0.3% | Sep 13, 2026 | The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after... |
| CVE-2026-90593 | HIGH | 7.3 | 0.4% | Sep 13, 2026 | A vulnerability was determined in embedded-graphics up to 0.8.2. This affects the function ImageRaw::draw_sub_image of t... |
| CVE-2026-88802 | HIGH | 7.5 | 0.2% | Sep 13, 2026 | The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3... |
| CVE-2026-88793 | HIGH | 8.8 | 0.3% | Sep 13, 2026 | The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions... |
| CVE-2026-85129 | HIGH | 8.8 | 0.3% | Sep 13, 2026 | The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import featu... |
| CVE-2026-74933 | HIGH | 8.8 | 0.3% | Sep 13, 2026 | The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJA... |
| CVE-2026-37008 | HIGH | 8.1 | 0.1% | Sep 13, 2026 | CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vu... |
| CVE-2026-36453 | HIGH | 7.4 | 0.2% | Sep 13, 2026 | Rhymix before 2.1.31 allows insecure direct object reference, aka RVE-2026-1. Arbitrary files can be accessed via extra ... |
| CVE-2026-29811 | HIGH | 7.7 | 0.3% | Sep 13, 2026 | CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a pr... |
| CVE-2026-90579 | HIGH | 7.3 | 0.4% | Sep 13, 2026 | A vulnerability has been found in cheshire-cat-ai Cheshire Cat AI up to 1.9.2. This affects the function _authorize_http... |
| CVE-2026-90566 | HIGH | 7.3 | 0.5% | Sep 13, 2026 | A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. A... |
| CVE-2026-90526 | HIGH | 7.3 | 0.4% | Sep 13, 2026 | A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unk... |
| CVE-2026-90524 | HIGH | 7.3 | 0.7% | Sep 13, 2026 | A security flaw has been discovered in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d30995... |
| CVE-2026-90523 | HIGH | 7.3 | 0.5% | Sep 13, 2026 | A vulnerability was identified in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af0... |
| CVE-2026-90783 | HIGH | 7.8 | 0.2% | Sep 13, 2026 | MKVToolNix through 101.0 contains a heap buffer overflow in the bundled avilib library's ODML superindex parser due to i... |
| CVE-2026-90522 | HIGH | 7.3 | 0.5% | Sep 13, 2026 | A vulnerability was determined in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938... |
| CVE-2026-90780 | HIGH | 7.5 | 0.6% | Sep 13, 2026 | SIPp through 3.7.7 contains a buffer overflow vulnerability in the get_header() function in src/sip_parser.cpp when proc... |
| CVE-2026-90779 | HIGH | 7.5 | 0.6% | Sep 13, 2026 | SIPp through 3.7.7 contains a stack buffer overflow vulnerability in createAuthHeader() when processing SIP authenticati... |
| CVE-2026-90778 | HIGH | 7.5 | 0.6% | Sep 13, 2026 | SIPp through 3.7.7 contains a buffer overflow vulnerability in get_peer_tag() function when processing SIP To headers wi... |
| CVE-2026-90777 | HIGH | 8.8 | 0.5% | Sep 13, 2026 | ESPnet before 202609 deserializes pretrained model checkpoints using torch.load with weights_only=False, allowing arbitr... |
| CVE-2026-90776 | HIGH | 7.5 | 0.7% | Sep 13, 2026 | Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser componen... |
| CVE-2026-90516 | HIGH | 7.3 | 0.4% | Sep 13, 2026 | A vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is an unknown f... |
| CVE-2026-90515 | HIGH | 7.3 | 0.3% | Sep 13, 2026 | A vulnerability was determined in SourceCodester School Registration and Fee System 1.0. The impacted element is an unkn... |
| CVE-2026-90774 | HIGH | 7.5 | 0.4% | Sep 13, 2026 | rustypaste before 0.18.1 validates the destination path before applying the optional custom filename HTTP header, allowi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now