2026 CVE Vulnerabilities
67,248 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-81469 | HIGH | 7.8 | 0.2% | Sep 21, 2026 | Dell Inventory Collector Client, versions prior to 15.0.0, contain an Unquoted Search Path or Element vulnerability. A l... |
| CVE-2026-79320 | MEDIUM | 6.1 | 0.1% | Sep 21, 2026 | Stencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vulnerability in the component runtime. When a downs... |
| CVE-2026-79319 | MEDIUM | 5.3 | 0.2% | Sep 21, 2026 | Stencil core 4.43.5 is vulnerable to Incorrect Access Control. |
| CVE-2026-79318 | MEDIUM | 6.5 | 0.2% | Sep 21, 2026 | web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file(... |
| CVE-2026-73552 | HIGH | 7.5 | 0.7% | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-73550 | HIGH | 7.5 | — | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-73549 | MEDIUM | 5.3 | 0.6% | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-73548 | HIGH | 7.5 | 0.7% | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-73547 | HIGH | 7.5 | 0.8% | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-73546 | HIGH | 7.4 | 0.6% | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-73513 | HIGH | 7.5 | — | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-73512 | HIGH | 7.5 | 0.8% | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-62247 | MEDIUM | 6.5 | 0.5% | Sep 21, 2026 | Supabase Realtime provides Broadcast, Presence, and Postgres Changes via WebSockets. Prior to 2.111.2, Realtime authoriz... |
| CVE-2026-58271 | MEDIUM | 6.8 | 0.3% | Sep 21, 2026 | Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0,... |
| CVE-2026-58269 | HIGH | 8.1 | 0.2% | Sep 21, 2026 | Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0,... |
| CVE-2026-55897 | HIGH | 8.8 | 0.7% | Sep 21, 2026 | luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router in... |
| CVE-2026-55159 | HIGH | 8.8 | — | Sep 21, 2026 | luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, ... |
| CVE-2026-54915 | MEDIUM | 5.4 | 0.4% | Sep 21, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the unauthenticated /aut... |
| CVE-2026-52835 | HIGH | 7 | — | Sep 21, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the import_config handle... |
| CVE-2026-50572 | MEDIUM | 5.9 | 0.7% | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-49995 | MEDIUM | 4.8 | — | Sep 21, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the newsletter cron fiel... |
| CVE-2026-49811 | HIGH | 8.4 | 0.1% | Sep 21, 2026 | Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect Permission Assignment for Critical Resourc... |
| CVE-2026-48521 | MEDIUM | 5.9 | 0.7% | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-45381 | MEDIUM | 5.1 | 0.6% | Sep 21, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the /search endpoint ins... |
| CVE-2026-94501 | HIGH | 8.8 | 0.3% | Sep 21, 2026 | jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authent... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now