2026 CVE Vulnerabilities
67,248 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15890 | MEDIUM | 5.3 | 0.1% | Sep 21, 2026 | The default AEAD nonce provider for the PSA Internal Trusted Storage transform module, secure_storage_its_transform_aead... |
| CVE-2026-94588 | MEDIUM | 4.4 | 0.2% | Sep 21, 2026 | In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is... |
| CVE-2026-94572 | CRITICAL | 9.4 | 0.5% | Sep 21, 2026 | In OpenStack Octavia before 18.0.1, the Amphora provider driver did not validate the listener and pool tls_ciphers field... |
| CVE-2026-94571 | CRITICAL | 9.4 | 0.3% | Sep 21, 2026 | In OpenStack Octavia before 18.0.1, the Amphora provider driver did not reject control characters in the L7 policy redir... |
| CVE-2026-94424 | HIGH | 8.8 | 0.1% | Sep 21, 2026 | A vulnerability has been found in Moore Threads MTT S80 Driver Package up to 340.150. Impacted is the function sub_14000... |
| CVE-2026-93433 | MEDIUM | 5.5 | 0.2% | Sep 21, 2026 | A flaw was found in libstoragemgmt. An attacker with control over a local or virtual storage device could provide specia... |
| CVE-2026-88746 | HIGH | 7.1 | 0.1% | Sep 21, 2026 | idccms V1.70 is vulnerable to Cross Site Scripting (XSS) in /admin/makeDiy_deal.php. |
| CVE-2026-88745 | MEDIUM | 6.1 | 0.1% | Sep 21, 2026 | EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers to upload a malicious shell. |
| CVE-2026-88467 | MEDIUM | 6.2 | 0.2% | Sep 21, 2026 | CRMEB Knowledge-Paid System crmeb_zzff_class 1.4.4 has a backend verification function that returns the wrong type of va... |
| CVE-2026-88412 | MEDIUM | 5.3 | 0.4% | Sep 21, 2026 | An integer overflow in the _BulkInsert_ReadProperty component (/bulk_insert.c) of FalkorDB (Redis module) v4.20.1 allows... |
| CVE-2026-88411 | HIGH | 7.5 | 0.3% | Sep 21, 2026 | Improper error handling in the GRAPH.EFFECT component (/effects/effects_apply.c) of FalkorDB (Redis module) v4.20.1 lead... |
| CVE-2026-88410 | HIGH | 7.1 | 0.2% | Sep 21, 2026 | The graph.UDF in FalkorDB (Redis module) v4.20.1 to v4.20.4 is not registered as a write command, leading to unexpected ... |
| CVE-2026-88409 | HIGH | 8.8 | 0.3% | Sep 21, 2026 | FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a buffer overflow in the _Decode_GrB_Matrix functio... |
| CVE-2026-88408 | MEDIUM | 6.5 | 0.2% | Sep 21, 2026 | FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _GetGroup() function (/ops/... |
| CVE-2026-88407 | HIGH | 7.5 | 0.5% | Sep 21, 2026 | An out-of-bounds read in the node_token_count/relation_token_count component of FalkorDB (Redis module) v4.20.1 to v4.20... |
| CVE-2026-88406 | HIGH | 7.5 | 0.3% | Sep 21, 2026 | FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _ValidateUnion_Clauses func... |
| CVE-2026-88405 | CRITICAL | 9.8 | 0.2% | Sep 21, 2026 | A remote code execution (RCE) vulnerability in the RemoteRegisterFunctionService function (/remote/remote-register-funct... |
| CVE-2026-88404 | CRITICAL | 9.8 | 0.2% | Sep 21, 2026 | A remote code execution (RCE) vulnerability in the UniscriptExecutionService.execute() function (/services/script-execut... |
| CVE-2026-88403 | MEDIUM | 6.5 | 0.2% | Sep 21, 2026 | A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to... |
| CVE-2026-88402 | CRITICAL | 9.8 | 0.2% | Sep 21, 2026 | A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive database ... |
| CVE-2026-79919 | MEDIUM | 6.3 | 0.3% | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, function-library code running under th... |
| CVE-2026-79918 | MEDIUM | 6.3 | 0.4% | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, the ToolExecutor LD_PRELOAD sandbox ho... |
| CVE-2026-79917 | MEDIUM | 6.5 | 0.2% | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. In 2.7.0 through 2.10.4-lts, POST /chat/api/{application_id}/chat/{... |
| CVE-2026-79916 | CRITICAL | 9.1 | 0.3% | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-lts, authenticated workspace members can inject con... |
| CVE-2026-79317 | MEDIUM | 4.8 | 0.2% | Sep 21, 2026 | A session invalidation flaw exists in x-ui 0.3.2. The full user object is stored in a client-side signed cookie, and aut... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now