2026 CVE Vulnerabilities
67,228 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-77637 | LOW | 3.8 | — | Sep 22, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, tool.GET("wopi") and tool.POST("mail") i... |
| CVE-2026-77633 | HIGH | 7.1 | 0.4% | Sep 22, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, PrepareUpload in pkg/filemanager/fs/dbfs... |
| CVE-2026-77621 | CRITICAL | 9.3 | 1.1% | Sep 22, 2026 | Vector is a high-performance observability data pipeline. From 0.10.0 until 0.57.0, the file sink renders its templated ... |
| CVE-2026-77620 | HIGH | 8.7 | 0.5% | Sep 22, 2026 | Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source feeds each decom... |
| CVE-2026-77619 | HIGH | 8.7 | 0.5% | Sep 22, 2026 | Vector is a high-performance observability data pipeline. From 0.15.0 until 0.57.0, the logstash source reads a 32-bit c... |
| CVE-2026-75608 | HIGH | 7.7 | — | Sep 22, 2026 | Frigate is an open source network video recorder. Prior to 0.18.0, the prefix-matched location /api/go2rtc/api in docker... |
| CVE-2026-75607 | HIGH | 8.1 | — | Sep 22, 2026 | Frigate is an open source network video recorder. Prior to 0.17.2, the WebSocket handler in frigate/comms/ws.py forwards... |
| CVE-2026-75517 | MEDIUM | 6.5 | 0.7% | Sep 22, 2026 | Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu integration mutation use... |
| CVE-2026-75511 | MEDIUM | 5.3 | 0.5% | Sep 22, 2026 | Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu accepts chat webhook URL... |
| CVE-2026-75510 | MEDIUM | 5.1 | 0.4% | Sep 22, 2026 | Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu's @novu/js In-App Inbox ... |
| CVE-2026-70410 | HIGH | 8.8 | — | Sep 22, 2026 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite Avati... |
| CVE-2026-63374 | CRITICAL | 9.3 | — | Sep 22, 2026 | AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Pri... |
| CVE-2026-56681 | HIGH | 7.3 | — | Sep 22, 2026 | 9Router is an AI router & token saver. Prior to 0.5.6, 9Router deployments that allow requests to reach Next.js without ... |
| CVE-2026-95754 | MEDIUM | 6.9 | — | Sep 22, 2026 | In MISP's UsersController login() method, the pre-authentication database query used for the TOTP (two-factor authentica... |
| CVE-2026-95703 | MEDIUM | 5.1 | — | Sep 22, 2026 | In MISP, the OrganisationsController::__uploadLogo method processed a caller-supplied tmp_name value with filesystem pro... |
| CVE-2026-95701 | MEDIUM | 5.1 | — | Sep 22, 2026 | In MISP, the __statisticsOrgs method in UsersController.php used the organization name directly as a file-system path co... |
| CVE-2026-95698 | MEDIUM | 5.3 | — | Sep 22, 2026 | The findOrgImage method in MISP's OrgImgHelper constructs a filesystem path by concatenating a user-supplied organizatio... |
| CVE-2026-95697 | MEDIUM | 5.3 | — | Sep 22, 2026 | MISP contains an authorization flaw in the Organisation model's captureOrg method. When the $force parameter is set to t... |
| CVE-2026-95693 | MEDIUM | 5.3 | — | Sep 22, 2026 | In MISP, the EventReport::uploadPicture method in processed a caller-supplied tmp_name field by invoking file_exists(), ... |
| CVE-2026-95685 | MEDIUM | 5.3 | — | Sep 22, 2026 | MISP contains an access control flaw in the EventReports functionality. The replaceSuggestionInReport action, which allo... |
| CVE-2026-95683 | MEDIUM | 5.3 | — | Sep 22, 2026 | In MISP, the Overmind event view enriches an event with its most recent attached report for preview purposes. The enrich... |
| CVE-2026-95501 | MEDIUM | 4.3 | — | Sep 22, 2026 | A vulnerability was found in mtrano APENCMS up to 6546096d354153309693efabb9a0d824628ed4f5. The affected element is the ... |
| CVE-2026-95500 | HIGH | 7.3 | — | Sep 22, 2026 | A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file... |
| CVE-2026-94570 | MEDIUM | 5.9 | — | Sep 22, 2026 | SGLang contains a DoS vulnerability caused by missing input validation for AUX_DATA ZeroMQ control messages in the Decod... |
| CVE-2026-94127 | CRITICAL | 9.8 | 1.4% | Sep 22, 2026 | When a BIG-IP APM access policy and an OAuth profile are configured on a virtual server, specific malicious traffic can ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now