2026 CVE Vulnerabilities
64,997 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-19301 | MEDIUM | 6.5 | 0.2% | Sep 4, 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to... |
| CVE-2026-19299 | MEDIUM | 6.5 | 0.5% | Sep 4, 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to... |
| CVE-2026-18887 | MEDIUM | 6.5 | 0.3% | Sep 4, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker ... |
| CVE-2026-18858 | MEDIUM | 5.5 | 0.1% | Sep 4, 2026 | IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SS... |
| CVE-2026-18567 | MEDIUM | 4.7 | 0.1% | Sep 4, 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a race condition involv... |
| CVE-2026-9186 | MEDIUM | 6.5 | 0.3% | Sep 4, 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration i... |
| CVE-2026-9138 | MEDIUM | 6.5 | 0.3% | Sep 4, 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the ser... |
| CVE-2026-8447 | MEDIUM | 6.1 | 0.2% | Sep 4, 2026 | IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site scripting vulnerability in the Playground chat int... |
| CVE-2026-85700 | MEDIUM | 6.5 | 0.3% | Sep 4, 2026 | Onyx 4.6.6 fails to properly restrict access to custom tool credentials stored in custom_headers, allowing any authentic... |
| CVE-2026-85698 | MEDIUM | 5.5 | 0.1% | Sep 4, 2026 | Turso through 0.8.0-pre.8 contains an out-of-bounds read vulnerability in the table-leaf page reader that uses an attack... |
| CVE-2026-85697 | MEDIUM | 6.5 | 0.4% | Sep 4, 2026 | Documenso 2.17.0 contains an access control vulnerability in the PDF-serving endpoint that fails to validate document vi... |
| CVE-2026-85693 | MEDIUM | 6.5 | 0.4% | Sep 4, 2026 | Chatbot UI contains an authorization bypass vulnerability in the retrieval endpoint that allows authenticated attackers ... |
| CVE-2026-85692 | MEDIUM | 6.5 | 0.3% | Sep 4, 2026 | Nightingale (n9e), as of commit 8362cbe (main branch, confirmed 2026-08-27), contains a server-side request forgery vuln... |
| CVE-2026-85689 | MEDIUM | 6.5 | 0.3% | Sep 4, 2026 | llmware 0.4.6 contains an SQL injection vulnerability in the collection-database layer (llmware/resources.py) where filt... |
| CVE-2026-85676 | MEDIUM | 4.3 | 0.2% | Sep 4, 2026 | Dub contains an open redirect vulnerability in the redir_url query parameter that is accepted on every short link withou... |
| CVE-2026-85670 | MEDIUM | 6.5 | 0.5% | Sep 4, 2026 | tokenizers (Hugging Face) is affected by an out-of-bounds buffer access in BpeBuilder::build (tokenizers/src/models/bpe/... |
| CVE-2026-85669 | MEDIUM | 6.5 | 0.2% | Sep 4, 2026 | potpie through 2.0.0 fails to verify user ownership on the POST /conversations/{conversation_id}/code-changes/sync endpo... |
| CVE-2026-85665 | MEDIUM | 6.5 | 0.7% | Sep 4, 2026 | Bruno versions through 4.1.0 fail to validate file paths in request body declarations, allowing attackers to read arbitr... |
| CVE-2026-85662 | MEDIUM | 5.3 | 0.3% | Sep 4, 2026 | Marqo 2.26.0 contains a server-side request forgery vulnerability in the add_documents endpoint that allows unauthentica... |
| CVE-2026-85650 | MEDIUM | 5.4 | 0.3% | Sep 4, 2026 | Trigger.dev before 4.5.2 contains a server-side request forgery vulnerability in webhook alert channel delivery URLs tha... |
| CVE-2026-85624 | MEDIUM | 6.5 | 0.4% | Sep 4, 2026 | Blinko 1.8.7 contains a cross-user private note disclosure vulnerability in the noteReferenceList procedure that perform... |
| CVE-2026-85622 | MEDIUM | 5.3 | 0.3% | Sep 4, 2026 | AppFlowy-Cloud through 0.9.64 fails to validate workspace membership when establishing WebSocket connections in the esta... |
| CVE-2026-85621 | MEDIUM | 6.5 | 0.2% | Sep 4, 2026 | LobeChat (LobeHub) 2.2.1 does not properly verify inbound chat-platform webhook signatures in the QQ and Feishu adapters... |
| CVE-2026-85618 | MEDIUM | 6.5 | 0.4% | Sep 4, 2026 | ConvertX 0.17.0 contains an arbitrary file read vulnerability in the xelatex converter that allows authenticated users t... |
| CVE-2026-85605 | MEDIUM | 5.3 | 0.4% | Sep 4, 2026 | Slink before 1.12.3 fails to properly authorize access to image comment endpoints, allowing unauthenticated attackers to... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now