2026 CVE Vulnerabilities
65,328 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100882 | LOW | 2.4 | — | Sep 27, 2026 | A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Web... |
| CVE-2026-100881 | LOW | 2.6 | — | Sep 27, 2026 | A security vulnerability has been detected in zhistaredu StarTraining up to 3.8.1. This issue affects some unknown proce... |
| CVE-2026-96281 | MEDIUM | 6.2 | — | Sep 27, 2026 | On a multi-user system, a user with an active local login session could downgrade a system-wide Flatpak app to an older ... |
| CVE-2026-96280 | HIGH | 7.5 | 0.6% | Sep 27, 2026 | The OCI delta stream parser read sizes as guint64 but passed them to GLib I/O and allocation functions expecting gsize (... |
| CVE-2026-101090 | CRITICAL | 9.8 | — | Sep 27, 2026 | Nezha 2.2.3 contains a Host header injection regression in the OAuth2 redirect endpoint. When the new optional dashboard... |
| CVE-2026-101089 | LOW | 3.1 | — | Sep 27, 2026 | Nezha before 2.2.7 contains an information disclosure vulnerability in the GET /api/v1/profile endpoint that returns the... |
| CVE-2026-101088 | MEDIUM | 5.3 | — | Sep 27, 2026 | Nezha is a server and website monitoring tool. In versions >= 2.2.11 and < 2.3.1, the service sentinel worker (service/s... |
| CVE-2026-101087 | MEDIUM | 4.3 | — | Sep 27, 2026 | Nezha versions 2.0.10 through 2.3.2 use a restricted HTTP client to validate user-configurable notification and DDNS web... |
| CVE-2026-101086 | MEDIUM | 6.5 | — | Sep 27, 2026 | Nezha Dashboard versions before 2.3.5 fail to restrict service monitor task types to supported probe types, allowing aut... |
| CVE-2026-101085 | MEDIUM | 6.5 | — | Sep 27, 2026 | Nezha before 2.3.8 fails to validate alert rule type and duration bounds, allowing authenticated non-administrator users... |
| CVE-2026-101084 | CRITICAL | 9.6 | — | Sep 27, 2026 | obot versions before v0.21.1 fail to enforce Access Control Rules on the /mcp-connect endpoint, allowing any authenticat... |
| CVE-2026-101065 | CRITICAL | 9.8 | — | Sep 27, 2026 | Obot is an open-source AI agent/MCP platform. In all versions up to and including commit d7e6970, the Docker quickstart ... |
| CVE-2026-101064 | HIGH | 7.6 | — | Sep 27, 2026 | Obot before v0.23.0 contains a server-side request forgery vulnerability in remote MCP server registration that allows p... |
| CVE-2026-101063 | MEDIUM | 5.3 | — | Sep 27, 2026 | Obot versions before v0.23.0 fail to enforce authentication on MCP Registry endpoints under /v0.1/* when registry authen... |
| CVE-2026-101062 | HIGH | 8.8 | — | Sep 27, 2026 | Obot before v0.23.0 (affected versions <= v0.22.1) running with OBOT_SERVER_ENABLE_AUTHENTICATION=true exposes OAuth dyn... |
| CVE-2026-100880 | LOW | 3.5 | — | Sep 27, 2026 | A weakness has been identified in zhistaredu StarTraining up to 3.8.1. This vulnerability affects unknown code of the fi... |
| CVE-2026-100879 | MEDIUM | 4.3 | — | Sep 27, 2026 | A security flaw has been discovered in zhistaredu StarTraining up to 3.8.1. This affects the function checkRoleAllowed o... |
| CVE-2026-100878 | MEDIUM | 6.3 | — | Sep 27, 2026 | A vulnerability was identified in zhistaredu StarTraining up to 3.8.1. Affected by this issue is the function SysUser.is... |
| CVE-2026-100877 | MEDIUM | 4.3 | — | Sep 27, 2026 | A vulnerability was determined in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be... |
| CVE-2026-96279 | MEDIUM | 6.5 | — | Sep 27, 2026 | A malicious OCI registry can hardlink arbitrary host files into the extraction directory when a user installs or updates... |
| CVE-2026-100876 | MEDIUM | 6.3 | — | Sep 27, 2026 | A vulnerability was found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Aff... |
| CVE-2026-100875 | HIGH | 7.3 | — | Sep 27, 2026 | A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be... |
| CVE-2026-100874 | HIGH | 7.3 | — | Sep 27, 2026 | A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This af... |
| CVE-2026-100873 | MEDIUM | 4.3 | — | Sep 27, 2026 | A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. ... |
| CVE-2026-101061 | MEDIUM | 4.7 | — | Sep 27, 2026 | utcp-gql before 1.1.1 and utcp-websocket before 1.1.1 contain server-side request forgery vulnerabilities due to incompl... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now