2026 CVE Vulnerabilities
67,248 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-79316 | HIGH | 7.6 | 0.2% | Sep 21, 2026 | An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configur... |
| CVE-2026-77525 | MEDIUM | 4.2 | 0.2% | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, management chat-record routes authorize ... |
| CVE-2026-77523 | HIGH | 7.4 | — | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the model parameter form route a... |
| CVE-2026-77522 | MEDIUM | 4.3 | 0.3% | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the knowledge web-document impor... |
| CVE-2026-77521 | CRITICAL | 10 | — | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skil... |
| CVE-2026-77520 | MEDIUM | 5.4 | 0.2% | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal user in the same workspace can ... |
| CVE-2026-77519 | MEDIUM | 5.4 | 0.3% | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, the /chat/api/mcp authentication path lo... |
| CVE-2026-77518 | MEDIUM | 5 | — | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal workspace user who knows anothe... |
| CVE-2026-77517 | MEDIUM | 5.4 | — | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.10.2-lts, document and paragraph opera... |
| CVE-2026-77516 | MEDIUM | 5.4 | — | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.9.2, a lowest-role workspace member de... |
| CVE-2026-73553 | HIGH | 7.5 | 0.5% | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-73551 | MEDIUM | 5.3 | — | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-73511 | MEDIUM | 5.3 | 0.6% | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-67827 | CRITICAL | 9.8 | 0.2% | Sep 21, 2026 | Incorrect Access Control in the HTTP API module in ZLMediaKit commit 9fd5152 allows remote attackers to achieve Remote C... |
| CVE-2026-61647 | HIGH | 7.1 | 0.3% | Sep 21, 2026 | NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content ... |
| CVE-2026-59816 | MEDIUM | 4.3 | 0.3% | Sep 21, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7... |
| CVE-2026-58272 | MEDIUM | 5.3 | 0.3% | Sep 21, 2026 | Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Versions prior to 2.4.1... |
| CVE-2026-58270 | MEDIUM | 6.5 | 0.3% | Sep 21, 2026 | Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0,... |
| CVE-2026-55179 | MEDIUM | 6.5 | 0.2% | Sep 21, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2... |
| CVE-2026-55105 | HIGH | 7.7 | 0.4% | Sep 21, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.1... |
| CVE-2026-49453 | HIGH | 7 | 0.3% | Sep 21, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.1... |
| CVE-2026-49450 | HIGH | 7.1 | 0.1% | Sep 21, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2... |
| CVE-2026-49449 | LOW | 2.5 | — | Sep 21, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. From 1.4.0 unt... |
| CVE-2026-46649 | CRITICAL | 9.1 | — | Sep 21, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2... |
| CVE-2026-85219 | LOW | 3.7 | 0.3% | Sep 21, 2026 | Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 allows an unauthenticated remote attacker cause u... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now