2026 CVE Vulnerabilities
64,704 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100692 | HIGH | 7.5 | — | Sep 26, 2026 | Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopp... |
| CVE-2026-100690 | HIGH | 7.5 | — | Sep 26, 2026 | Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.j... |
| CVE-2026-100686 | HIGH | 8.1 | — | Sep 26, 2026 | Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endp... |
| CVE-2026-100685 | HIGH | 7.7 | — | Sep 26, 2026 | Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enume... |
| CVE-2026-100684 | HIGH | 8.1 | — | Sep 26, 2026 | Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. ... |
| CVE-2026-100683 | HIGH | 8 | — | Sep 26, 2026 | Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backend-core/src/sql/sqlT... |
| CVE-2026-100682 | HIGH | 8.8 | — | Sep 26, 2026 | Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extrac... |
| CVE-2026-100680 | HIGH | 8.1 | — | Sep 26, 2026 | Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validat... |
| CVE-2026-100679 | HIGH | 8.8 | — | Sep 26, 2026 | stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypas... |
| CVE-2026-100676 | HIGH | 8.2 | — | Sep 26, 2026 | January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 improperly resolves SVG... |
| CVE-2026-100673 | HIGH | 8.2 | — | Sep 26, 2026 | The Grav Data Manager plugin (getgrav/grav-plugin-datamanager) versions 1.0.1 through 1.4.4 render stored data entries i... |
| CVE-2026-100672 | HIGH | 7.5 | — | Sep 26, 2026 | The Comments plugin (getgrav/grav-plugin-comments) for Grav CMS through version 1.2.10 registers an admin handler that r... |
| CVE-2026-100671 | HIGH | 8 | — | Sep 26, 2026 | Grav is a flat-file CMS. In versions 2.0.19 through 2.0.24 — and in 2.0.0 through 2.0.18 and 1.7.x only where content Tw... |
| CVE-2026-100670 | HIGH | 8.8 | — | Sep 26, 2026 | Grav CMS 2.0.14 through 2.0.24 contains a privilege escalation vulnerability in the group and account blueprints. The ac... |
| CVE-2026-100669 | HIGH | 7.5 | — | Sep 26, 2026 | Grav before 2.0.25 ships web server configuration samples whose access-control deny rules are matched case-sensitively. ... |
| CVE-2026-100666 | HIGH | 7.3 | — | Sep 26, 2026 | Netty's HttpServerCodec (io.netty:netty-codec-http) in versions 4.2.0.Final through 4.2.16.Final and in versions up to a... |
| CVE-2026-100665 | HIGH | 7.5 | — | Sep 26, 2026 | Netty versions from 4.2.11.Final before 4.2.18.Final contain an incomplete hostname verification fix in the QUIC certifi... |
| CVE-2026-100664 | HIGH | 7.5 | — | Sep 26, 2026 | Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.2.Final through 4.2.17.Final builds the HTTP/3 :authority... |
| CVE-2026-100663 | HIGH | 7.5 | — | Sep 26, 2026 | Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.2.Final through 4.2.17.Final does not special-case HTTP/1 CON... |
| CVE-2026-100662 | HIGH | 7.5 | — | Sep 26, 2026 | Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain an uncontrolled reso... |
| CVE-2026-100661 | HIGH | 7.5 | — | Sep 26, 2026 | Netty's HTTP/3 codec (io.netty:netty-codec-http3) versions 4.2.0.Final through 4.2.17.Final contain a denial-of-service ... |
| CVE-2026-100660 | HIGH | 7.5 | — | Sep 26, 2026 | Netty's HTTP/3 codec (io.netty:netty-codec-http3) from 4.2.0.Final through 4.2.17.Final retains unbounded per-stream QPA... |
| CVE-2026-100657 | HIGH | 7.5 | — | Sep 26, 2026 | Netty's STOMP codec (io.netty:netty-codec-stomp) contains a ByteBuf leak in StompSubframeDecoder. Once a frame's declare... |
| CVE-2026-100656 | HIGH | 7.5 | — | Sep 26, 2026 | Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue growth flaw in HttpServerCodec. The codec t... |
| CVE-2026-100655 | HIGH | 7.5 | — | Sep 26, 2026 | Netty (io.netty:netty-codec-http) versions up to and including 4.1.137.Final and from 4.2.0.Final through 4.2.17.Final a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now