2026 CVE Vulnerabilities
64,751 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56792 | MEDIUM | 4.4 | 0.1% | Sep 24, 2026 | Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low priv... |
| CVE-2026-52853 | MEDIUM | 5.2 | — | Sep 24, 2026 | Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace ADMIN ... |
| CVE-2026-52850 | MEDIUM | 4.3 | — | Sep 24, 2026 | Docmost is open-source collaborative wiki and documentation software. Prior to 0.90.1, an authenticated workspace member... |
| CVE-2026-48073 | MEDIUM | 4.3 | — | Sep 24, 2026 | Docmost is open-source collaborative wiki and documentation software. From 0.70.0 until 0.80.1, a low-privileged authent... |
| CVE-2026-48072 | MEDIUM | 5.3 | — | Sep 24, 2026 | Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, the public avatar and logo image ... |
| CVE-2026-97232 | MEDIUM | 6.3 | — | Sep 24, 2026 | A vulnerability was determined in volotat Anagnorisis up to 0.4.2. Affected by this vulnerability is the function get_fi... |
| CVE-2026-93405 | MEDIUM | 6.1 | — | Sep 24, 2026 | Mailspring is a fast, cross-platform, open-source email client. Prior to 1.17.0, attachment quick preview converts Markd... |
| CVE-2026-91121 | MEDIUM | 5 | — | Sep 24, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, attacker-controlle... |
| CVE-2026-91120 | MEDIUM | 5.4 | — | Sep 24, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, provider-controlle... |
| CVE-2026-91119 | MEDIUM | 6.4 | — | Sep 24, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the topic small-ac... |
| CVE-2026-81508 | MEDIUM | 4.3 | — | Sep 24, 2026 | ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In 5.5.5, 6.0.1, and 6.1, the BlueDroid A2DP si... |
| CVE-2026-61811 | MEDIUM | 6.5 | — | Sep 24, 2026 | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. F... |
| CVE-2026-61784 | MEDIUM | 6.1 | — | Sep 24, 2026 | xhtml-purifier is a Node.js library to take in raw/unknown/untrusted HTML and output cleaned, purified, trusted HTML. Ve... |
| CVE-2026-57179 | MEDIUM | 4.2 | — | Sep 24, 2026 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resum... |
| CVE-2026-57177 | MEDIUM | 4.3 | — | Sep 24, 2026 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend di... |
| CVE-2026-57176 | MEDIUM | 6.8 | — | Sep 24, 2026 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend us... |
| CVE-2026-57175 | MEDIUM | 6.4 | — | Sep 24, 2026 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted ... |
| CVE-2026-54461 | MEDIUM | 6.5 | — | Sep 24, 2026 | Habitica is a habit tracker application that treats goals like a role-playing game. From 4.172.1 until 5.48.2, a query p... |
| CVE-2026-94281 | MEDIUM | 6.5 | — | Sep 24, 2026 | An out-of-bounds read in libXi's XListInputDevices() class parsing in libXi before 1.8.4 could be used by malicious X se... |
| CVE-2026-93545 | MEDIUM | 6.5 | — | Sep 24, 2026 | An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash... |
| CVE-2026-93544 | MEDIUM | 6.5 | — | Sep 24, 2026 | An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X serv... |
| CVE-2026-93542 | MEDIUM | 6.5 | — | Sep 24, 2026 | An out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be ... |
| CVE-2026-91161 | MEDIUM | 6.4 | — | Sep 24, 2026 | OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior to 0.23.5, the GET /api/sessions/{sessionId}/grou... |
| CVE-2026-91134 | MEDIUM | 5.4 | — | Sep 24, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the Discourse post... |
| CVE-2026-91133 | MEDIUM | 6.5 | — | Sep 24, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, authenticated user... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now