2026 CVE Vulnerabilities
67,269 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-94393 | MEDIUM | 6.4 | — | Sep 21, 2026 | When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without prope... |
| CVE-2026-94387 | MEDIUM | 5.4 | — | Sep 21, 2026 | Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_v... |
| CVE-2026-94382 | MEDIUM | 4.2 | 0.2% | Sep 21, 2026 | Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-... |
| CVE-2026-93884 | — | — | — | Sep 21, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All r... |
| CVE-2026-88807 | HIGH | 8.9 | 0.3% | Sep 21, 2026 | A heap overflow in libXrender before 0.9.13 in RenderQueryPictFormats could be used by malicious X servers to inject cod... |
| CVE-2026-88806 | HIGH | 7.5 | 0.2% | Sep 21, 2026 | A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing th... |
| CVE-2026-85220 | LOW | 3.7 | 0.3% | Sep 21, 2026 | A vulnerability in the Thinkst Canary honeypot Redis service allows an unauthenticated remote attacker to execute a Deni... |
| CVE-2026-94383 | HIGH | 8.6 | — | Sep 21, 2026 | The MISP blocklist workflow module accepted a user-supplied blocklist filename parameter without validating the file ext... |
| CVE-2026-94381 | HIGH | 8.7 | — | Sep 21, 2026 | MISP has a security issue that can let a user gain more access than their API key is supposed to allow. A read-only API... |
| CVE-2026-94379 | MEDIUM | 6.9 | — | Sep 21, 2026 | The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-cr... |
| CVE-2026-94374 | HIGH | 8.3 | — | Sep 21, 2026 | MISP contains an insecure direct object reference vulnerability in the processModuleResultsData method of the Event mode... |
| CVE-2026-94373 | MEDIUM | 6.3 | — | Sep 21, 2026 | MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript component. The Cont... |
| CVE-2026-94372 | MEDIUM | 6.3 | — | Sep 21, 2026 | MISP contains a stored cross-site scripting (XSS) vulnerability in the default theme's Galaxies index page. When a MISP ... |
| CVE-2026-94216 | MEDIUM | 4.3 | 0.5% | Sep 21, 2026 | A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution. This vulnerability ... |
| CVE-2026-94214 | MEDIUM | 4.3 | 0.5% | Sep 21, 2026 | A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affe... |
| CVE-2026-94211 | LOW | 2.4 | — | Sep 21, 2026 | A vulnerability has been found in Hyve5 Leantime up to 3.9.8. Affected by this issue is some unknown functionality of th... |
| CVE-2026-84285 | HIGH | 8.8 | — | Sep 21, 2026 | An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker... |
| CVE-2026-94368 | HIGH | 7.1 | 0.1% | Sep 21, 2026 | A flaw was found in the signature verification logic of noobaa-core, the core component of the NooBaa Multicloud Object ... |
| CVE-2026-94210 | LOW | 3.5 | — | Sep 21, 2026 | A flaw has been found in Hyve5 Leantime up to 3.9.8. Affected by this vulnerability is the function getAllGrouped of the... |
| CVE-2026-91867 | MEDIUM | 4.3 | 0.3% | Sep 21, 2026 | When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server tha... |
| CVE-2026-91866 | HIGH | 7.5 | 0.5% | Sep 21, 2026 | A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work... |
| CVE-2026-91865 | HIGH | 7.5 | 0.5% | Sep 21, 2026 | A small WS-Policy document using repeated policy references can force Neethi to re-expand the same references exponentia... |
| CVE-2026-91864 | HIGH | 7.5 | 0.5% | Sep 21, 2026 | A specially crafted WS-Policy document can pack unlimited content inside a policy assertion, which Neethi copies into me... |
| CVE-2026-91863 | HIGH | 7.5 | 0.5% | Sep 21, 2026 | A specially crafted WS-Policy document with deeply nested policy elements can bypass Neethi's nesting-depth limit and ex... |
| CVE-2026-89139 | HIGH | 8.7 | 0.5% | Sep 21, 2026 | Temporal Server compiles a Worker Controller Instance module into its Worker Service, and that module registers a comput... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now