2026 CVE Vulnerabilities
67,418 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-77610 | MEDIUM | 6.1 | 0.3% | Sep 18, 2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ... |
| CVE-2026-77609 | MEDIUM | 6.1 | 0.2% | Sep 18, 2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ... |
| CVE-2026-77608 | MEDIUM | 6.1 | 0.3% | Sep 18, 2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ... |
| CVE-2026-77607 | MEDIUM | 6.1 | 0.2% | Sep 18, 2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ... |
| CVE-2026-77606 | MEDIUM | 6.1 | 0.3% | Sep 18, 2026 | Semantic MediaWiki is a free, open-source extension to MediaWiki that lets users store and query data within the wiki's ... |
| CVE-2026-77339 | MEDIUM | 5.1 | 0.3% | Sep 18, 2026 | Process Compose is a scheduler and orchestrator for non-containerized applications. Prior to 1.120.0, the MCP SSE listen... |
| CVE-2026-77301 | HIGH | 7.5 | 0.6% | Sep 18, 2026 | adm-zip is a JavaScript library for creating and extracting ZIP archives in Node.js. Prior to 0.6.1, getData() in zipEnt... |
| CVE-2026-77240 | CRITICAL | 9.9 | 0.3% | Sep 18, 2026 | WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, the profiles_update row-level security... |
| CVE-2026-77239 | HIGH | 8.1 | 0.3% | Sep 18, 2026 | WACRM is a self-hostable CRM template for WhatsApp. In version 0.7.0 and earlier, WACRM flow and automation write routes... |
| CVE-2026-73863 | HIGH | 7 | 0.4% | Sep 18, 2026 | NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's broker-side MQTT v5 nmq_subinfo_decode() function in nng/src/sp/pro... |
| CVE-2026-63406 | MEDIUM | 5.9 | 0.3% | Sep 18, 2026 | AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the telemet... |
| CVE-2026-63405 | MEDIUM | 5.9 | 0.2% | Sep 18, 2026 | AnyCable is a realtime server for reliable two-way communication that supports any backend. Prior to 1.6.15, the Pusher-... |
| CVE-2026-63349 | HIGH | 7 | 0.1% | Sep 18, 2026 | AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. In ... |
| CVE-2026-62943 | HIGH | 8.7 | 0.5% | Sep 18, 2026 | btrbk is a tool for creating snapshots and remote backups of Btrfs subvolumes. From 0.29.0 until 0.32.7, btrbk's ssh_fil... |
| CVE-2026-61833 | HIGH | 8.1 | 0.5% | Sep 18, 2026 | zot is a container image and artifact registry based on the Open Container Initiative Distribution Specification. Prior ... |
| CVE-2026-61795 | MEDIUM | 6.8 | 0.6% | Sep 18, 2026 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, hostnameRegexHandler.OnU... |
| CVE-2026-61794 | MEDIUM | 6.8 | 0.6% | Sep 18, 2026 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.7, the Tenant update valida... |
| CVE-2026-61672 | HIGH | 7.1 | 0.3% | Sep 18, 2026 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.7, ForbiddenListSpec.ExactMatch in p... |
| CVE-2026-61633 | LOW | 2 | — | Sep 18, 2026 | NanoMQ is an MQTT broker. Prior to 0.24.14, the NanoMQ client function nni_mqtt_msg_decode_unsubscribe() in nng/src/supp... |
| CVE-2026-61548 | HIGH | 8.1 | 0.9% | Sep 18, 2026 | Rsyslog is a rocket-fast system for log processing. From 7.5.4 until 8.2606.0, the optional mmpstrucdata plugin's parseS... |
| CVE-2026-58197 | HIGH | 8.8 | 0.4% | Sep 18, 2026 | ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to Too... |
| CVE-2026-55556 | HIGH | 8.2 | 1.1% | Sep 18, 2026 | Rsyslog is a rocket-fast system for log processing. From 8.2110.0 until 8.2604.0, the optional imhttp module's parse_aut... |
| CVE-2026-46655 | HIGH | 7.8 | 0.2% | Sep 18, 2026 | virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits... |
| CVE-2026-44639 | LOW | 3.7 | — | Sep 18, 2026 | NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's MQTT v5 property decoder in nng/src/supplemental/mqtt/mqtt_codec.c ... |
| CVE-2026-93737 | MEDIUM | 6.5 | 0.3% | Sep 18, 2026 | Azkaban through 4.0.0 omits project permission checks in the ScheduleServlet fetchSchedule action, allowing authenticate... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now