2026 CVE Vulnerabilities
64,997 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-52773 | MEDIUM | 6.1 | 0.5% | Sep 5, 2026 | YesWiki is a wiki system written in PHP. From version 4.1.0 to before version 4.6.6, YesWiki's archived-revision view re... |
| CVE-2026-52772 | MEDIUM | 5.5 | 0.2% | Sep 5, 2026 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar form-field templates still apply |raw('html') to ... |
| CVE-2026-52763 | MEDIUM | 6.5 | 0.2% | Sep 5, 2026 | YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the recentchanges action (actions/recentchanges.php) ac... |
| CVE-2026-86097 | MEDIUM | 6.5 | 0.2% | Sep 4, 2026 | PX4 Autopilot through 1.17.0 contains a null pointer dereference vulnerability in param_set_default_file() and param_set... |
| CVE-2026-86096 | MEDIUM | 5.9 | 0.2% | Sep 4, 2026 | PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in TemperatureCalibration::start() due to a race co... |
| CVE-2026-76925 | MEDIUM | 5.8 | 0.1% | Sep 4, 2026 | A flaw was found in Flatpak. A Time-of-check to time-of-use (TOCTOU) race condition exists in the `org.freedesktop.Flatp... |
| CVE-2026-85787 | MEDIUM | 6.5 | 0.2% | Sep 4, 2026 | An incomplete list of disallowed inputs in the SQL validation component in Amazon awslabs postgres-mcp-server before ve... |
| CVE-2026-85703 | MEDIUM | 6.5 | 0.3% | Sep 4, 2026 | A flaw has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. Affected by this iss... |
| CVE-2026-85701 | MEDIUM | 5.3 | 0.4% | Sep 4, 2026 | A vulnerability has been found in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This issue ... |
| CVE-2026-77847 | MEDIUM | 6.5 | 0.3% | Sep 4, 2026 | Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a use of hard-coded credential vulnerability... |
| CVE-2026-53769 | MEDIUM | 6.5 | 0.3% | Sep 4, 2026 | Avo is a framework to create admin panels for Ruby on Rails apps. From version 2.28.0 to before version 3.32.0, Avo's di... |
| CVE-2026-85643 | MEDIUM | 4.7 | 0.2% | Sep 4, 2026 | A flaw has been found in code-projects Online Shopping System 1.0. Impacted is the function mysqli_query of the file adm... |
| CVE-2026-55513 | MEDIUM | 5.4 | 0.2% | Sep 4, 2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.3.0 to before version 0.5.0, the ne... |
| CVE-2026-55512 | MEDIUM | 5.3 | 0.3% | Sep 4, 2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. From version 0.2.0 to before version 0.5.0, when O... |
| CVE-2026-53602 | MEDIUM | 6.9 | 0.2% | Sep 4, 2026 | nebula-mesh is a self-hosted control plane for Slack Nebula mesh VPN. Prior to version 0.3.7, two related authorization ... |
| CVE-2026-85639 | MEDIUM | 5.6 | 0.2% | Sep 4, 2026 | A security vulnerability has been detected in jofpin trape 2.0. This vulnerability affects unknown code of the file core... |
| CVE-2026-85637 | MEDIUM | 5.3 | 0.4% | Sep 4, 2026 | A security flaw has been discovered in jofpin trape 1.0.0/2.0. Affected by this issue is the function join_room of the f... |
| CVE-2026-80115 | MEDIUM | 6.1 | 0.1% | Sep 4, 2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 10... |
| CVE-2026-85769 | MEDIUM | 6.5 | 0.4% | Sep 4, 2026 | A flaw was found in libtpms, a library that provides software TPM 2.0 emulation. When restoring TPM 2.0 state (for examp... |
| CVE-2026-85636 | MEDIUM | 5.3 | 0.4% | Sep 4, 2026 | A vulnerability was identified in jofpin trape 1.0.0. Affected by this vulnerability is an unknown functionality of the ... |
| CVE-2026-84890 | MEDIUM | 5.9 | 0.3% | Sep 4, 2026 | undici's decompress interceptor decompresses response bodies according to the untrusted Content-Encoding header. While t... |
| CVE-2026-73848 | MEDIUM | 6.9 | 0.3% | Sep 4, 2026 | Emlog is an open source website building system. In versions 2.6.29 and prior, tag names in emlog are not HTML-encoded w... |
| CVE-2026-61688 | MEDIUM | 6.5 | 0.3% | Sep 4, 2026 | SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, an authenticated user can view the API reques... |
| CVE-2026-61614 | MEDIUM | 5.9 | 0.3% | Sep 4, 2026 | SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, the REST API authenticator accepts bearer tok... |
| CVE-2026-61608 | MEDIUM | 6.8 | 0.2% | Sep 4, 2026 | SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, `UserInvitation` entities have no expiry time... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now