2026 CVE Vulnerabilities
64,952 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-82054 | MEDIUM | 6.5 | 0.3% | Sep 8, 2026 | A security issue exists in MongoDB server's JSON Pointer parser used during $jsonSchema query filter processing. When a ... |
| CVE-2026-82052 | MEDIUM | 6.5 | 0.4% | Sep 8, 2026 | The $regexFindAll expression can be used by an authenticated user who can run aggregation pipeline stages to crash a Mon... |
| CVE-2026-81531 | MEDIUM | 6.9 | 0.4% | Sep 8, 2026 | An information disclosure vulnerability has been identified in Omada Controller. An API endpoint intended for Controlle... |
| CVE-2026-78230 | MEDIUM | 6 | — | Sep 8, 2026 | AshAi exposes Ash read actions to language-model tool calls. The read tool accepts an aggregate result type (min, max, s... |
| CVE-2026-78216 | MEDIUM | 6 | — | Sep 8, 2026 | AshLua exposes Ash read actions to Lua scripts run through an eval action. A read call accepts an operation (list, min, ... |
| CVE-2026-52307 | MEDIUM | 5.4 | 0.3% | Sep 8, 2026 | An authenticated stored cross-site scripting (XSS) vulnerability in the Column Management component of ClassCMS 1CMS v5.... |
| CVE-2026-22575 | MEDIUM | 4.9 | — | Sep 8, 2026 | An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10... |
| CVE-2026-86853 | MEDIUM | 4.3 | — | Sep 8, 2026 | A malicious webpage could repeatedly trigger external URL schemes, causing system prompts or external application launch... |
| CVE-2026-86737 | MEDIUM | 4.3 | 0.2% | Sep 8, 2026 | snipe-it versions before 8.7.0 fail to enforce asset view authorization in the GET /hardware/{asset}/barcode endpoint. A... |
| CVE-2026-86736 | MEDIUM | 4.3 | 0.2% | Sep 8, 2026 | snipe-it before 8.7.0 contains an incorrect calculation vulnerability in checkout request handling that allows authentic... |
| CVE-2026-86735 | MEDIUM | 5 | — | Sep 8, 2026 | snipe-it versions before 8.7.0 contain a server-side request forgery vulnerability in the ExternalUrl validation rule th... |
| CVE-2026-86734 | MEDIUM | 6.5 | 0.3% | Sep 8, 2026 | Snipe-IT before 8.7.1 fails to validate the length of the note field in the POST /account/accept/{acceptance} endpoint, ... |
| CVE-2026-86731 | MEDIUM | 6.5 | 0.2% | Sep 8, 2026 | Craft CMS versions 5.0.0-RC1 through 5.10.11 are missing an admin-target guard in UsersController::actionActivateUser (t... |
| CVE-2026-86726 | MEDIUM | 6.5 | 0.3% | Sep 8, 2026 | AVideo through 29.0 contains an information disclosure vulnerability in restreamsActive.json.php that allows authenticat... |
| CVE-2026-86724 | MEDIUM | 6.5 | 0.1% | Sep 8, 2026 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in pl... |
| CVE-2026-86719 | MEDIUM | 5.4 | 0.1% | Sep 8, 2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master) contains a cross-site request forgery vulne... |
| CVE-2026-79573 | MEDIUM | 6.5 | 0.2% | Sep 8, 2026 | L-ONE v1.0.0 was discovered to contain multiple SQL injection vulnerabilities in the /attachment/getBusinessUploadList c... |
| CVE-2026-56101 | MEDIUM | 5.3 | 0.4% | Sep 8, 2026 | OpenBSD before commit 1ee99df contains an inverted comparison vulnerability in the ieee80211_michael_mic_failure() funct... |
| CVE-2026-84282 | MEDIUM | 6.5 | 0.2% | Sep 8, 2026 | A Server-Side Request Forgery (SSRF) vulnerability exists in the ONLYOFFICE ownCloud Integration plugin version 9.12. Th... |
| CVE-2026-12387 | MEDIUM | 5.1 | 0.1% | Sep 8, 2026 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge... |
| CVE-2026-12285 | MEDIUM | 4 | 0.1% | Sep 8, 2026 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge... |
| CVE-2026-11891 | MEDIUM | 5.1 | 0.1% | Sep 8, 2026 | Use After Free vulnerability in Arm Ltd Valhall GPU Userspace Driver, Arm Ltd Arm 5th Gen GPU Architecture Userspace Dri... |
| CVE-2026-0001 | MEDIUM | 4.4 | — | Sep 8, 2026 | Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Ge... |
| CVE-2026-79379 | MEDIUM | 6.5 | 0.2% | Sep 8, 2026 | A buffer overflow in the SBC_DecodeFrames() function of Bestechnic Co., Ltd BES2300 Bluetooth Audio SoC firmware v3.x an... |
| CVE-2026-78838 | MEDIUM | 6.5 | 0.2% | Sep 8, 2026 | A reflected cross-site scripting (XSS) vulnerability in the grid_datasource.php component of AppNitro MachForm v30 allow... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now