2026 CVE Vulnerabilities
64,766 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-81878 | MEDIUM | 5.5 | 0.2% | Sep 22, 2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's CPython bytecod... |
| CVE-2026-79913 | MEDIUM | 6.5 | — | Sep 22, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, the ValidateExternalURL server-side requ... |
| CVE-2026-79312 | MEDIUM | 6.8 | — | Sep 22, 2026 | webpy web.py 0.76 is vulnerable to Session Fixation. The component Session._load() reads session_id directly from the re... |
| CVE-2026-75517 | MEDIUM | 6.5 | 0.7% | Sep 22, 2026 | Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu integration mutation use... |
| CVE-2026-75511 | MEDIUM | 5.3 | 0.5% | Sep 22, 2026 | Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu accepts chat webhook URL... |
| CVE-2026-75510 | MEDIUM | 5.1 | 0.4% | Sep 22, 2026 | Novu provides an API for sending notifications through multiple channels. Prior to 3.18.0, Novu's @novu/js In-App Inbox ... |
| CVE-2026-95754 | MEDIUM | 6.9 | — | Sep 22, 2026 | In MISP's UsersController login() method, the pre-authentication database query used for the TOTP (two-factor authentica... |
| CVE-2026-95703 | MEDIUM | 5.1 | — | Sep 22, 2026 | In MISP, the OrganisationsController::__uploadLogo method processed a caller-supplied tmp_name value with filesystem pro... |
| CVE-2026-95701 | MEDIUM | 5.1 | — | Sep 22, 2026 | In MISP, the __statisticsOrgs method in UsersController.php used the organization name directly as a file-system path co... |
| CVE-2026-95698 | MEDIUM | 5.3 | — | Sep 22, 2026 | The findOrgImage method in MISP's OrgImgHelper constructs a filesystem path by concatenating a user-supplied organizatio... |
| CVE-2026-95697 | MEDIUM | 5.3 | — | Sep 22, 2026 | MISP contains an authorization flaw in the Organisation model's captureOrg method. When the $force parameter is set to t... |
| CVE-2026-95693 | MEDIUM | 5.3 | — | Sep 22, 2026 | In MISP, the EventReport::uploadPicture method in processed a caller-supplied tmp_name field by invoking file_exists(), ... |
| CVE-2026-95685 | MEDIUM | 5.3 | — | Sep 22, 2026 | MISP contains an access control flaw in the EventReports functionality. The replaceSuggestionInReport action, which allo... |
| CVE-2026-95683 | MEDIUM | 5.3 | — | Sep 22, 2026 | In MISP, the Overmind event view enriches an event with its most recent attached report for preview purposes. The enrich... |
| CVE-2026-95501 | MEDIUM | 4.3 | — | Sep 22, 2026 | A vulnerability was found in mtrano APENCMS up to 6546096d354153309693efabb9a0d824628ed4f5. The affected element is the ... |
| CVE-2026-94570 | MEDIUM | 5.9 | — | Sep 22, 2026 | SGLang contains a DoS vulnerability caused by missing input validation for AUX_DATA ZeroMQ control messages in the Decod... |
| CVE-2026-93344 | MEDIUM | 6.5 | — | Sep 22, 2026 | MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_get_page_... |
| CVE-2026-79315 | MEDIUM | 4.7 | — | Sep 22, 2026 | A reflected cross-site scripting vulnerability exists in x-ui 0.3.2. The management interface reflects the raw request U... |
| CVE-2026-65129 | MEDIUM | 6.7 | — | Sep 22, 2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate v... |
| CVE-2026-65127 | MEDIUM | 4.1 | — | Sep 22, 2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause exposure of sensitive ... |
| CVE-2026-65126 | MEDIUM | 5 | — | Sep 22, 2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper enforcement o... |
| CVE-2026-65125 | MEDIUM | 6.6 | — | Sep 22, 2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause external control of a ... |
| CVE-2026-65124 | MEDIUM | 5.9 | — | Sep 22, 2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an XML injection. A su... |
| CVE-2026-65117 | MEDIUM | 5 | — | Sep 22, 2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of a hard-coded pa... |
| CVE-2026-65115 | MEDIUM | 6.5 | — | Sep 22, 2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker may cause uncontrolled resource co... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now