2026 CVE Vulnerabilities
65,007 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56128 | MEDIUM | 5.4 | 0.4% | Sep 3, 2026 | pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Schedules: Edit privilege to ... |
| CVE-2026-56127 | MEDIUM | 5.4 | 0.4% | Sep 3, 2026 | pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Firewall: Rules: Edit privilege to inje... |
| CVE-2026-56126 | MEDIUM | 5.4 | 0.4% | Sep 3, 2026 | pfSense Plus before 26.07 and CE before 2.9.0 allow authenticated users with the Status: Monitoring privilege to inject ... |
| CVE-2026-35160 | MEDIUM | 5 | — | Sep 3, 2026 | Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements use... |
| CVE-2026-84815 | MEDIUM | 5.8 | — | Sep 3, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Kriesi Enfold allo... |
| CVE-2026-85173 | MEDIUM | 4.3 | 0.3% | Sep 3, 2026 | n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that all... |
| CVE-2026-85172 | MEDIUM | 6.4 | 0.3% | Sep 3, 2026 | n8n versions before 2.34.1 contain a server-side request forgery vulnerability in the legacy request helper function exp... |
| CVE-2026-85171 | MEDIUM | 6.5 | 0.4% | Sep 3, 2026 | n8n before 1.123.73, 2.35.4, and 2.36.2 contains a credential exposure vulnerability in the Strapi, SeaTable, and Mailch... |
| CVE-2026-85170 | MEDIUM | 6.5 | 0.2% | Sep 3, 2026 | n8n versions before 1.123.73, 2.35.4, and 2.36.2 pass message content in the Gmail (v1) and Brevo nodes to the mail comp... |
| CVE-2026-85167 | MEDIUM | 6.5 | 0.2% | Sep 3, 2026 | n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection vulnerability in the Elasticsearch Document Get All... |
| CVE-2026-85166 | MEDIUM | 6.5 | 0.2% | Sep 3, 2026 | n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate credential references in the inline workflow JSON of nodes ... |
| CVE-2026-85163 | MEDIUM | 6.5 | 0.2% | Sep 3, 2026 | AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the EPG parser that allows authe... |
| CVE-2026-85162 | MEDIUM | 6.5 | 0.1% | Sep 3, 2026 | AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in plugin/Live/saveLive.php that lac... |
| CVE-2026-85161 | MEDIUM | 4.3 | 0.1% | Sep 3, 2026 | AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in removePoster.php that lacks forbi... |
| CVE-2026-85159 | MEDIUM | 5.4 | 0.2% | Sep 3, 2026 | AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php where the cance... |
| CVE-2026-85158 | MEDIUM | 5.4 | 0.2% | Sep 3, 2026 | AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in videoEmbeded.php that echoes ... |
| CVE-2026-85157 | MEDIUM | 5.3 | 0.2% | Sep 3, 2026 | WWBN AVideo contains a broken access control vulnerability in the unauthenticated feed/index.php endpoint that disables ... |
| CVE-2026-85156 | MEDIUM | 5.3 | 0.2% | Sep 3, 2026 | WWBN AVideo fails to properly validate access controls on the public channel page, allowing unauthenticated visitors to ... |
| CVE-2026-85107 | MEDIUM | 4.3 | — | Sep 3, 2026 | A vulnerability was found in NousResearch hermes-agent 0.18.0. This vulnerability affects the function resourceBufferFro... |
| CVE-2026-85106 | MEDIUM | 6.3 | 0.2% | Sep 3, 2026 | A vulnerability has been found in NousResearch hermes-agent 0.18.0. This affects the function fetchLinkTitle of the file... |
| CVE-2026-85100 | MEDIUM | 4.3 | 0.5% | Sep 3, 2026 | A vulnerability was detected in 2FastLabs agent-squad up to 1.1.4. Affected by this vulnerability is the function AgentS... |
| CVE-2026-85093 | MEDIUM | 6.5 | 0.3% | Sep 3, 2026 | Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when retriev... |
| CVE-2026-85092 | MEDIUM | 6.6 | 0.2% | Sep 3, 2026 | LiME through 1.12.0 fails to validate the disk acquisition output path and does not use O_NOFOLLOW when opening the oper... |
| CVE-2026-85090 | MEDIUM | 5.4 | 0.3% | Sep 3, 2026 | FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during A... |
| CVE-2026-85089 | MEDIUM | 6.5 | 0.4% | Sep 3, 2026 | FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserv... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now