2026 CVE Vulnerabilities
64,766 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-77522 | MEDIUM | 4.3 | 0.3% | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the knowledge web-document impor... |
| CVE-2026-77520 | MEDIUM | 5.4 | 0.2% | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal user in the same workspace can ... |
| CVE-2026-77519 | MEDIUM | 5.4 | 0.3% | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, the /chat/api/mcp authentication path lo... |
| CVE-2026-77518 | MEDIUM | 5 | — | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal workspace user who knows anothe... |
| CVE-2026-77517 | MEDIUM | 5.4 | — | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.10.2-lts, document and paragraph opera... |
| CVE-2026-77516 | MEDIUM | 5.4 | — | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.9.2, a lowest-role workspace member de... |
| CVE-2026-73551 | MEDIUM | 5.3 | 0.6% | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-73511 | MEDIUM | 5.3 | 0.6% | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-59816 | MEDIUM | 4.3 | 0.3% | Sep 21, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.7... |
| CVE-2026-58272 | MEDIUM | 5.3 | 0.3% | Sep 21, 2026 | Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Versions prior to 2.4.1... |
| CVE-2026-58270 | MEDIUM | 6.5 | 0.3% | Sep 21, 2026 | Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0,... |
| CVE-2026-55179 | MEDIUM | 6.5 | 0.2% | Sep 21, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2... |
| CVE-2026-79320 | MEDIUM | 6.1 | 0.1% | Sep 21, 2026 | Stencil core 4.43.5 contains a DOM-based cross-site scripting (XSS) vulnerability in the component runtime. When a downs... |
| CVE-2026-79319 | MEDIUM | 5.3 | 0.2% | Sep 21, 2026 | Stencil core 4.43.5 is vulnerable to Incorrect Access Control. |
| CVE-2026-79318 | MEDIUM | 6.5 | 0.2% | Sep 21, 2026 | web2py 3.2.2-stable (commit a7330a2bf21219fa77860b6665de927dd4f98e6d) is vulnerable to Directory Traversal in read_file(... |
| CVE-2026-73549 | MEDIUM | 5.3 | 0.6% | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-62247 | MEDIUM | 6.5 | 0.5% | Sep 21, 2026 | Supabase Realtime provides Broadcast, Presence, and Postgres Changes via WebSockets. Prior to 2.111.2, Realtime authoriz... |
| CVE-2026-58271 | MEDIUM | 6.8 | 0.3% | Sep 21, 2026 | Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0,... |
| CVE-2026-54915 | MEDIUM | 5.4 | 0.4% | Sep 21, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the unauthenticated /aut... |
| CVE-2026-50572 | MEDIUM | 5.9 | 0.7% | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-49995 | MEDIUM | 4.8 | — | Sep 21, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the newsletter cron fiel... |
| CVE-2026-48521 | MEDIUM | 5.9 | 0.7% | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-45381 | MEDIUM | 5.1 | — | Sep 21, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the /search endpoint ins... |
| CVE-2026-94494 | MEDIUM | 5 | 0.2% | Sep 21, 2026 | jshERP through 3.6 contains a tenant isolation bypass vulnerability that allows authenticated users to read other tenant... |
| CVE-2026-94414 | MEDIUM | 5.4 | 0.2% | Sep 21, 2026 | jshERP through 3.6 is missing an authorization check on the POST /userBusiness/updateBtnStr endpoint that allows authent... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now