2026 CVE Vulnerabilities
68,769 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-92756 | MEDIUM | 5.5 | 0.1% | Sep 17, 2026 | Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this prov... |
| CVE-2026-57846 | — | — | — | Sep 17, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-54752 | CRITICAL | 9.6 | 0.7% | Sep 17, 2026 | NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The vali... |
| CVE-2026-54716 | HIGH | 7.5 | 0.5% | Sep 17, 2026 | Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. In 3.7.0 and earli... |
| CVE-2026-54692 | HIGH | 7.8 | 0.2% | Sep 17, 2026 | SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. P... |
| CVE-2026-54627 | CRITICAL | 9.8 | 0.4% | Sep 17, 2026 | SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. I... |
| CVE-2026-54626 | CRITICAL | 9.8 | 0.8% | Sep 17, 2026 | SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. I... |
| CVE-2026-54618 | CRITICAL | 9.4 | 0.5% | Sep 17, 2026 | Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authoriza... |
| CVE-2026-54594 | MEDIUM | 5.3 | 0.3% | Sep 17, 2026 | OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/d... |
| CVE-2026-54495 | MEDIUM | 4.3 | 0.3% | Sep 17, 2026 | The OpenFeature Operator allows users to expose feature flags to applications. In version 0.9.2 and earlier, a tenant wh... |
| CVE-2026-50285 | HIGH | 7.5 | 0.7% | Sep 17, 2026 | Pomerium is an identity and context-aware access proxy. Prior to 0.32.8, decodeQueryStringV2 in pkg/hpke/url.go performs... |
| CVE-2026-50125 | HIGH | 7.5 | 0.5% | Sep 17, 2026 | MKP is a Model Context Protocol server for Kubernetes. Prior to 0.4.1, cmd/server/main.go exposes the default HTTP endpo... |
| CVE-2026-45726 | HIGH | 7.6 | 0.1% | Sep 17, 2026 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. From 1.3.0 until 1.6.6 and 1.7.3, importing a st... |
| CVE-2026-45723 | LOW | 2.7 | 0.4% | Sep 17, 2026 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.Creat... |
| CVE-2026-45720 | HIGH | 7 | 0.1% | Sep 17, 2026 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and from 1.7.0 until 1.7.3, SAML.... |
| CVE-2026-92992 | MEDIUM | 6.3 | — | Sep 17, 2026 | A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown functio... |
| CVE-2026-92230 | HIGH | 7.5 | — | Sep 17, 2026 | Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container thr... |
| CVE-2026-90997 | HIGH | 7.4 | 0.4% | Sep 17, 2026 | A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics b... |
| CVE-2026-55062 | HIGH | 8.4 | 0.2% | Sep 17, 2026 | uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget... |
| CVE-2026-55061 | LOW | 1 | 0.2% | Sep 17, 2026 | uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget... |
| CVE-2026-54649 | LOW | 2.1 | 0.8% | Sep 17, 2026 | punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Pr... |
| CVE-2026-54617 | CRITICAL | 9.8 | 1.1% | Sep 17, 2026 | GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote ... |
| CVE-2026-54571 | HIGH | 8.7 | 0.5% | Sep 17, 2026 | ESPAsyncWebServer is an asynchronous HTTP and WebSocket server library for ESP32, ESP8266, RP2040 and RP2350. Prior to 3... |
| CVE-2026-54524 | HIGH | 7.1 | 0.5% | Sep 17, 2026 | Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user with the ... |
| CVE-2026-54504 | HIGH | 8.8 | 0.6% | Sep 17, 2026 | MCP Documentation Server is a local-first document management and semantic search server for AI coding agents. From 1.13... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now