2026 CVE Vulnerabilities
64,766 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-94533 | MEDIUM | 6.5 | 0.3% | Sep 21, 2026 | lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in FileAnyoneController that allows authenticat... |
| CVE-2026-94532 | MEDIUM | 6.5 | 0.4% | Sep 21, 2026 | lamp-cloud through 5.10.0 contains an authorization bypass vulnerability in the getUserInfoById endpoint that allows aut... |
| CVE-2026-93340 | MEDIUM | 6.8 | 0.3% | Sep 21, 2026 | Gladys Assistant before 5.1.0 contains a password reset link poisoning vulnerability that allows unauthenticated remote ... |
| CVE-2026-88756 | MEDIUM | 5.3 | 0.2% | Sep 21, 2026 | Pagekit CMS <= 1.0.18 allows an unauthenticated attacker to perform SQL injection through the credentials array submitte... |
| CVE-2026-78806 | MEDIUM | 5.5 | 0.1% | Sep 21, 2026 | An issue in Matter Standard Specification-Implementation gap v1.5.1 Matter Project Chip V1.5.1 allows a local attacker t... |
| CVE-2026-61852 | MEDIUM | 5.8 | 0.5% | Sep 21, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-61851 | MEDIUM | 6.5 | 0.5% | Sep 21, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-61743 | MEDIUM | 6.3 | 0.4% | Sep 21, 2026 | Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create c... |
| CVE-2026-61541 | MEDIUM | 6.9 | 0.3% | Sep 21, 2026 | Zapros, a Python HTTP client, prior to version 0.14.0 is vulnerable to denial of service when an application requests co... |
| CVE-2026-59830 | MEDIUM | 5.4 | 0.2% | Sep 21, 2026 | Discourse is an open-source discussion platform. Prior to 2026.7.0, the post action component failed to escape user-cont... |
| CVE-2026-59815 | MEDIUM | 4.3 | 0.3% | Sep 21, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7... |
| CVE-2026-46650 | MEDIUM | 4.4 | 0.2% | Sep 21, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2... |
| CVE-2026-17054 | MEDIUM | 5.3 | 0.2% | Sep 21, 2026 | The Espressif ESP-hosted Wi-Fi driver (drivers/wifi/esp_hosted/) parses frames received over SPI from the ESP co-process... |
| CVE-2026-15890 | MEDIUM | 5.3 | 0.1% | Sep 21, 2026 | The default AEAD nonce provider for the PSA Internal Trusted Storage transform module, secure_storage_its_transform_aead... |
| CVE-2026-94588 | MEDIUM | 4.4 | 0.2% | Sep 21, 2026 | In Proxmox pmg-api, an argument injection vulnerability exists in the package changelog retrieval functionality. This is... |
| CVE-2026-93433 | MEDIUM | 5.5 | 0.2% | Sep 21, 2026 | A flaw was found in libstoragemgmt. An attacker with control over a local or virtual storage device could provide specia... |
| CVE-2026-88745 | MEDIUM | 6.1 | 0.1% | Sep 21, 2026 | EMLOG-Pro 2.6.29 contains a XSS vulnerability that enables attackers to upload a malicious shell. |
| CVE-2026-88412 | MEDIUM | 5.3 | 0.4% | Sep 21, 2026 | An integer overflow in the _BulkInsert_ReadProperty component (/bulk_insert.c) of FalkorDB (Redis module) v4.20.1 allows... |
| CVE-2026-88408 | MEDIUM | 6.5 | 0.2% | Sep 21, 2026 | FalkorDB (Redis module) v4.20.1 to v4.20.4 was discovered to contain a stack overflow in the _GetGroup() function (/ops/... |
| CVE-2026-88403 | MEDIUM | 6.5 | 0.2% | Sep 21, 2026 | A Server-Side Request Forgery (SSRF) in the serverRequest function of nocobase v2.1.21 allows authenticated attackers to... |
| CVE-2026-79919 | MEDIUM | 6.3 | 0.3% | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, function-library code running under th... |
| CVE-2026-79918 | MEDIUM | 6.3 | 0.4% | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, the ToolExecutor LD_PRELOAD sandbox ho... |
| CVE-2026-79917 | MEDIUM | 6.5 | 0.2% | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. In 2.7.0 through 2.10.4-lts, POST /chat/api/{application_id}/chat/{... |
| CVE-2026-79317 | MEDIUM | 4.8 | 0.2% | Sep 21, 2026 | A session invalidation flaw exists in x-ui 0.3.2. The full user object is stored in a client-side signed cookie, and aut... |
| CVE-2026-77525 | MEDIUM | 4.2 | 0.2% | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, management chat-record routes authorize ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now