2026 CVE Vulnerabilities
64,751 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-82585 | MEDIUM | 6.5 | 0.1% | Sep 24, 2026 | The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An at... |
| CVE-2026-79959 | MEDIUM | 6.8 | 0.2% | Sep 24, 2026 | The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. A... |
| CVE-2026-75558 | MEDIUM | 5.3 | 0.2% | Sep 24, 2026 | The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi cre... |
| CVE-2026-14442 | MEDIUM | 6.9 | — | Sep 24, 2026 | An information exposure vulnerability in the job scheduling component of SANnav allows sensitive credentials to be writt... |
| CVE-2026-14441 | MEDIUM | 6.9 | 0.4% | Sep 24, 2026 | A logic flaw in Java cache key handling object comparison handling could lead to improper identifier resolution when pro... |
| CVE-2026-97365 | MEDIUM | 6.3 | — | Sep 24, 2026 | A vulnerability was determined in chonkie-inc littrs 0.6.1/0.6.2. Impacted is the function Sandbox::mount of the file cr... |
| CVE-2026-97325 | MEDIUM | 4.3 | 0.3% | Sep 24, 2026 | A security flaw has been discovered in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected by this vulnerability ... |
| CVE-2026-93290 | MEDIUM | 5.5 | — | Sep 24, 2026 | Omni C20 uses hard-coded credentials that could allow an attacker to monitor log files to obtain credentials to access i... |
| CVE-2026-88956 | MEDIUM | 6.8 | 0.2% | Sep 24, 2026 | The Botslab G980H dash camera firmware contains an authentication vulnerability in the root account exposed through the ... |
| CVE-2026-88761 | MEDIUM | 5.3 | 0.2% | Sep 24, 2026 | The Botslab G980H dash camera firmware generates the default WiFi password using predictable device information, portion... |
| CVE-2026-48543 | MEDIUM | 5.4 | 0.1% | Sep 24, 2026 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attack... |
| CVE-2026-48542 | MEDIUM | 5.4 | — | Sep 24, 2026 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attack... |
| CVE-2026-48541 | MEDIUM | 5.4 | — | Sep 24, 2026 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attack... |
| CVE-2026-48540 | MEDIUM | 5.4 | — | Sep 24, 2026 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attack... |
| CVE-2026-97323 | MEDIUM | 6.3 | — | Sep 24, 2026 | A vulnerability was determined in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This impacts the function getOrigina... |
| CVE-2026-97322 | MEDIUM | 4.3 | — | Sep 24, 2026 | A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. This affects an unknown function of the f... |
| CVE-2026-97321 | MEDIUM | 6.3 | — | Sep 24, 2026 | A vulnerability has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The impacted element is the function... |
| CVE-2026-97320 | MEDIUM | 6.3 | 0.2% | Sep 24, 2026 | A flaw has been found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. The affected element is the function AiKnowle... |
| CVE-2026-96748 | MEDIUM | 6.5 | — | Sep 24, 2026 | PyMongo's connection string parsing decodes percent-encoded characters in the host portion before the host list is separ... |
| CVE-2026-96747 | MEDIUM | 5 | — | Sep 24, 2026 | The client-side field level encryption support in the MongoDB Python Driver can treat a key management endpoint value en... |
| CVE-2026-85738 | MEDIUM | 6.3 | — | Sep 24, 2026 | TREK is a collaborative travel planner. Prior to 3.4.0, the checkSsrf logic in server/src/utils/ssrfGuard.ts does not re... |
| CVE-2026-77321 | MEDIUM | 4.3 | — | Sep 24, 2026 | TREK is a collaborative travel planner. Prior to 3.3.0, the get_trip_summary tool in server/src/mcp/tools/trips.ts is re... |
| CVE-2026-77320 | MEDIUM | 5.3 | — | Sep 24, 2026 | TREK is a collaborative travel planner. Prior to 3.3.0, getSharedTripData in server/src/services/shareService.ts returns... |
| CVE-2026-65827 | MEDIUM | 6.5 | — | Sep 24, 2026 | Docmost is open-source collaborative wiki and documentation software. From 0.21.0 until 0.95.0, any authenticated worksp... |
| CVE-2026-62286 | MEDIUM | 4.3 | — | Sep 24, 2026 | Dozzle is a realtime log viewer for docker containers. Prior to 10.6.7, streamEvents in internal/web/events.go applies a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now