2026 CVE Vulnerabilities
64,704 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100681 | MEDIUM | 5.4 | — | Sep 26, 2026 | Budibase before 3.45.0 contains an unauthenticated server-side request forgery and credential exfiltration vulnerability... |
| CVE-2026-100678 | MEDIUM | 6.5 | — | Sep 26, 2026 | stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who kn... |
| CVE-2026-100677 | MEDIUM | 5.3 | — | Sep 26, 2026 | stoatchat before 0.15.5 contains an account enumeration vulnerability in the login endpoint that exposes source file loc... |
| CVE-2026-100675 | MEDIUM | 6.5 | — | Sep 26, 2026 | stoatchat versions before 0.15.5 contain a denial of service vulnerability in the acknowledgement worker that processes ... |
| CVE-2026-100674 | MEDIUM | 4.3 | — | Sep 26, 2026 | stoatchat before 0.15.5 fails to revalidate usernames after Unicode sanitization, allowing attackers to create usernames... |
| CVE-2026-100668 | MEDIUM | 6.5 | — | Sep 26, 2026 | Grav 2.0.0 through 2.0.24 contain a Twig content sandbox escape. The `array` filter (and its identical function form) is... |
| CVE-2026-100667 | MEDIUM | 5.3 | — | Sep 26, 2026 | grav-plugin-login (the Grav CMS Login plugin) versions >= 3.8.7 and < 3.9.7 allow the two-factor authentication challeng... |
| CVE-2026-100659 | MEDIUM | 6.5 | — | Sep 26, 2026 | Netty's HTTP/3 codec (io.netty:netty-codec-http3) in versions 4.2.0.Final through 4.2.17.Final does not enforce the RFC ... |
| CVE-2026-100658 | MEDIUM | 5.3 | — | Sep 26, 2026 | Netty (io.netty:netty-codec-http) contains an unbounded per-connection queue in WebSocketServerExtensionHandler. The han... |
| CVE-2026-100654 | MEDIUM | 6.5 | — | Sep 26, 2026 | vLLM before 0.29.0 accepts user-controlled stop_token_ids on the OpenAI-compatible POST /v1/completions and POST /v1/cha... |
| CVE-2026-100653 | MEDIUM | 6.5 | — | Sep 26, 2026 | vLLM is an inference and serving engine for large language models. In versions from 0.22.1 through 0.28.0, the operator-... |
| CVE-2026-100652 | MEDIUM | 5.9 | — | Sep 26, 2026 | vLLM versions 0.22.0 through 0.23.0 fail to validate stop_token_ids against vocabulary bounds in Rust HTTP and gRPC fron... |
| CVE-2026-100651 | MEDIUM | 6.5 | — | Sep 26, 2026 | vLLM before 0.29.0 fails to enforce decoder prompt-length validation on the disaggregated serving endpoint /inference/v1... |
| CVE-2026-100650 | MEDIUM | 6.5 | — | Sep 26, 2026 | vLLM through 0.29.0 fetches and fully materializes remote or inline media before enforcing its documented media controls... |
| CVE-2026-100648 | MEDIUM | 5.3 | — | Sep 26, 2026 | vllm before 0.29.0 fails to enforce VLLM_MAX_AUDIO_CLIP_FILESIZE_MB limit in multimodal chat audio decoding, allowing un... |
| CVE-2026-100647 | MEDIUM | 5.3 | — | Sep 26, 2026 | vLLM versions before 0.29.0 contain a denial-of-service vulnerability in the cache_salt parameter accepted on OpenAI-com... |
| CVE-2026-100640 | MEDIUM | 4.7 | — | Sep 26, 2026 | SiYuan before v3.8.4 contains an authorization omission in the siyuan-get IPC handler that allows remote-kernel renderer... |
| CVE-2026-100635 | MEDIUM | 5.9 | — | Sep 26, 2026 | SiYuan before v3.8.4 contains an authentication bypass vulnerability in the publish service where session cookies are is... |
| CVE-2026-100634 | MEDIUM | 4.7 | — | Sep 26, 2026 | SiYuan before v3.8.4 does not validate the sender or restrict recipients in the 'siyuan-send-windows' IPC handler of the... |
| CVE-2026-100633 | MEDIUM | 6.5 | — | Sep 26, 2026 | SiYuan is a self-hosted personal knowledge management system. In versions 3.8.0 through 3.8.3, the MCP file tool's sensi... |
| CVE-2026-100632 | MEDIUM | 6.5 | — | Sep 26, 2026 | Parse Server is an open-source backend server. In versions >= 9.0.0 and < 9.10.1-alpha.8, and in versions < 8.6.89, Live... |
| CVE-2026-100630 | MEDIUM | 5.4 | — | Sep 26, 2026 | AVideo contains a stored cross-site scripting vulnerability in the video trailer1 field rendered unsanitized within an i... |
| CVE-2026-100629 | MEDIUM | 5.5 | — | Sep 26, 2026 | Capgo (capgo.app backend) before 12.127.5 contains an authorization flaw in the PATCH /private/role_bindings/:binding_id... |
| CVE-2026-100628 | MEDIUM | 4.3 | — | Sep 26, 2026 | capgo.app before 12.128.12 fails to enforce an organization's API key expiration policy when creating app-scoped API key... |
| CVE-2026-100626 | MEDIUM | 4.3 | — | Sep 26, 2026 | capgo through 12.128.2 contains an insecure direct object reference vulnerability in the PUT /app/:appId endpoint that a... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now