2026 CVE Vulnerabilities
67,251 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48521 | MEDIUM | 5.9 | 0.7% | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-45381 | MEDIUM | 5.1 | 0.6% | Sep 21, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the /search endpoint ins... |
| CVE-2026-94501 | HIGH | 8.8 | 0.3% | Sep 21, 2026 | jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authent... |
| CVE-2026-94497 | HIGH | 8.3 | 0.3% | Sep 21, 2026 | jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resour... |
| CVE-2026-94496 | HIGH | 8.3 | 0.3% | Sep 21, 2026 | jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to mo... |
| CVE-2026-94495 | HIGH | 7.1 | 0.4% | Sep 21, 2026 | jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authen... |
| CVE-2026-94494 | MEDIUM | 5 | 0.2% | Sep 21, 2026 | jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenant... |
| CVE-2026-94414 | MEDIUM | 5.4 | 0.2% | Sep 21, 2026 | jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows authent... |
| CVE-2026-94413 | MEDIUM | 6.5 | 0.3% | Sep 21, 2026 | jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve ... |
| CVE-2026-94412 | HIGH | 8.8 | 0.3% | Sep 21, 2026 | jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authen... |
| CVE-2026-94411 | HIGH | 8.8 | 0.5% | Sep 21, 2026 | jshERP 3.6 contains a privilege escalation vulnerability in the updateOneValueByKeyIdAndType endpoint that allows authen... |
| CVE-2026-94403 | HIGH | 8.8 | 0.1% | Sep 21, 2026 | A weakness has been identified in ColorFul iGameCenter 1.0.3.4. This impacts the function sub_140001AF0 in the library e... |
| CVE-2026-91167 | MEDIUM | 6 | 0.4% | Sep 21, 2026 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.28.4, PUT /@warpgate/admin/api/users/... |
| CVE-2026-91166 | MEDIUM | 5.7 | 0.3% | Sep 21, 2026 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.25.0 until 0.27.6, the browser SSH path i... |
| CVE-2026-91165 | LOW | 2.4 | 0.4% | Sep 21, 2026 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.27.6, the response_mode=form_post SSO... |
| CVE-2026-91164 | MEDIUM | 4.3 | 0.4% | Sep 21, 2026 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.23.0 until 0.27.3, HTTP API token authent... |
| CVE-2026-82165 | MEDIUM | 5.5 | 0.1% | Sep 21, 2026 | Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions vu... |
| CVE-2026-82163 | MEDIUM | 5.5 | 0.1% | Sep 21, 2026 | Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contain an Incorrect Default Permissions vulnerability. ... |
| CVE-2026-66280 | — | — | — | Sep 21, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-63330 | HIGH | 7.7 | 0.4% | Sep 21, 2026 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, api_get_recording_stream in war... |
| CVE-2026-63329 | MEDIUM | 4.9 | 0.3% | Sep 21, 2026 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, copy_server_request in warpgate... |
| CVE-2026-61749 | MEDIUM | 6.5 | 0.5% | Sep 21, 2026 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, privileged staff users who can author report or... |
| CVE-2026-61748 | MEDIUM | 4.3 | 0.4% | Sep 21, 2026 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, ReportPrint at POST /api/report/print/ and Labe... |
| CVE-2026-61747 | MEDIUM | 4.3 | 0.3% | Sep 21, 2026 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the /api/importer/row/ and /api/importer/mappin... |
| CVE-2026-61746 | MEDIUM | 5.3 | 0.4% | Sep 21, 2026 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, PluginSettingList, PluginAllSettingList, and Pl... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now