2026 CVE Vulnerabilities
67,770 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54596 | HIGH | 8.1 | 0.5% | Sep 17, 2026 | ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to versi... |
| CVE-2026-54565 | MEDIUM | 4.7 | 0.2% | Sep 17, 2026 | rhwp is an HWP viewer and editor implemented in Rust and WebAssembly. Prior to rhwp 0.7.15 and rhwp Chrome and Firefox e... |
| CVE-2026-54521 | MEDIUM | 6.1 | 0.2% | Sep 17, 2026 | FairEmail is a fully featured, open source, privacy-friendly email app for Android. Prior to 1.2319, the ActivityAMP AMP... |
| CVE-2026-54510 | HIGH | 7.1 | — | Sep 17, 2026 | Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.21-alpha, the... |
| CVE-2026-54501 | CRITICAL | 9.4 | 1.8% | Sep 17, 2026 | Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through... |
| CVE-2026-54460 | CRITICAL | 9.8 | 0.7% | Sep 17, 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1... |
| CVE-2026-54355 | MEDIUM | 5.3 | 0.5% | Sep 17, 2026 | MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML outpu... |
| CVE-2026-54354 | HIGH | 8.2 | 0.7% | Sep 17, 2026 | MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime filter tran... |
| CVE-2026-54339 | HIGH | 7.7 | 0.5% | Sep 17, 2026 | Glean is a self-hosted RSS reader and personal knowledge management tool. Prior to 0.2.6, POST /api/feeds/discover passe... |
| CVE-2026-54237 | CRITICAL | 9.3 | 0.8% | Sep 17, 2026 | Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /instal... |
| CVE-2026-52483 | HIGH | 8.8 | 0.4% | Sep 17, 2026 | The ping diagnostics and other similar functions of the MitraStar GPT-2741GNAC-N2-SV router with firmware BR_g8.10_1.11(... |
| CVE-2026-50277 | HIGH | 7.5 | 0.8% | Sep 17, 2026 | dd-trace-cpp is the Datadog distributed tracing library for C++. Prior to 2.1.0, dd-trace-cpp parses incoming W3C baggag... |
| CVE-2026-50275 | HIGH | 7.5 | 0.5% | Sep 17, 2026 | The Datadog PHP Tracer provides application performance monitoring and distributed tracing for PHP. Prior to 1.19.2, ddt... |
| CVE-2026-50022 | MEDIUM | 5.8 | 0.3% | Sep 17, 2026 | Metacat is data repository software that helps researchers preserve, share, and discover data. Prior to 3.4.2, MetacatSo... |
| CVE-2026-49137 | — | — | — | Sep 17, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-48977 | HIGH | 7.7 | 0.3% | Sep 17, 2026 | OpenSlide is a C library for reading whole slide image files. From 3.4.1 until 4.0.1, OpenSlide's parse_level0_xml() pro... |
| CVE-2026-45143 | CRITICAL | 9 | 0.5% | Sep 17, 2026 | Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private ... |
| CVE-2026-45140 | CRITICAL | 9.8 | 1.3% | Sep 17, 2026 | Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote a... |
| CVE-2026-15815 | HIGH | 8.8 | 0.9% | Sep 17, 2026 | Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plug... |
| CVE-2026-11314 | — | — | — | Sep 17, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-10594 | — | — | — | Sep 17, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-93337 | HIGH | 7.8 | 0.1% | Sep 17, 2026 | NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains an improper input validation vulnerability that allows loc... |
| CVE-2026-92993 | MEDIUM | 6.3 | 1.5% | Sep 17, 2026 | A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of... |
| CVE-2026-92943 | HIGH | 8.1 | — | Sep 17, 2026 | Improper validation of certificate with host mismatch in the MQTT client TLS connection layer in AWS IoT Device SDK for ... |
| CVE-2026-92758 | MEDIUM | 5.5 | 0.2% | Sep 17, 2026 | If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now