2026 CVE Vulnerabilities
67,245 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-94535 | HIGH | 7.1 | 0.3% | Sep 21, 2026 | lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the deleteMyNotice endpoint that allows auth... |
| CVE-2026-94534 | HIGH | 7.1 | 0.3% | Sep 21, 2026 | lamp-cloud through 5.10.0 fails to validate user identity in PUT /anyone/baseInfo and PUT /anyone/avatar endpoints, allo... |
| CVE-2026-94533 | MEDIUM | 6.5 | 0.3% | Sep 21, 2026 | lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticat... |
| CVE-2026-94532 | MEDIUM | 6.5 | 0.4% | Sep 21, 2026 | lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows aut... |
| CVE-2026-93340 | MEDIUM | 6.8 | 0.3% | Sep 21, 2026 | Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote ... |
| CVE-2026-88756 | MEDIUM | 5.3 | 0.2% | Sep 21, 2026 | Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQL injection through the credentials array submitte... |
| CVE-2026-88738 | HIGH | 8.8 | 0.2% | Sep 21, 2026 | Jazzware RT1000 Edge webUI v. 20.0.1 contains an unrestricted file upload vulnerability in the upgrade package upload fu... |
| CVE-2026-79079 | HIGH | 7.8 | 0.2% | Sep 21, 2026 | An issue in CrossWire Xiphos <= 4.3.2 allows a local attacker to execute arbitrary code via the src/main/url.cc and src/... |
| CVE-2026-78847 | CRITICAL | 9.8 | 0.2% | Sep 21, 2026 | An issue in gray-matter All versions (verified on 4.0.3) allows the JavaScript engine in lib/engines.js using eval() to ... |
| CVE-2026-78806 | MEDIUM | 5.5 | 0.1% | Sep 21, 2026 | An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker t... |
| CVE-2026-65980 | HIGH | 7.9 | — | Sep 21, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-61852 | MEDIUM | 5.8 | 0.5% | Sep 21, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-61851 | MEDIUM | 6.5 | 0.5% | Sep 21, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-61743 | MEDIUM | 6.3 | 0.4% | Sep 21, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-61652 | HIGH | 8.7 | 0.4% | Sep 21, 2026 | Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service via memory exhaustion. The issu... |
| CVE-2026-61541 | MEDIUM | 6.9 | 0.4% | Sep 21, 2026 | Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service when an application requests co... |
| CVE-2026-59830 | MEDIUM | 5.4 | 0.2% | Sep 21, 2026 | Discourse is an open-source discussion platform. Prior to 2026.7.0, the post action component failed to escape user-cont... |
| CVE-2026-59815 | MEDIUM | 4.3 | 0.3% | Sep 21, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7... |
| CVE-2026-59814 | HIGH | 7.6 | 0.3% | Sep 21, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7... |
| CVE-2026-55210 | HIGH | 7.4 | 0.4% | Sep 21, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2... |
| CVE-2026-46650 | MEDIUM | 4.4 | — | Sep 21, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2... |
| CVE-2026-17054 | MEDIUM | 5.3 | 0.2% | Sep 21, 2026 | The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parses frames received over SPI from the ESP co-process... |
| CVE-2026-15890 | MEDIUM | 5.3 | 0.1% | Sep 21, 2026 | The default AEAD nonce provider for the PSA Internal Trusted Storage transform module, secure_storage_its_transform_aead... |
| CVE-2026-94588 | MEDIUM | 4.4 | 0.2% | Sep 21, 2026 | In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is... |
| CVE-2026-94572 | CRITICAL | 9.4 | 0.5% | Sep 21, 2026 | In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now