2026 CVE Vulnerabilities
64,766 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-94413 | MEDIUM | 6.5 | 0.3% | Sep 21, 2026 | jshERP through 3.6 fails to redact password hashes in the /user/info endpoint, allowing authenticated users to retrieve ... |
| CVE-2026-91167 | MEDIUM | 6 | 0.4% | Sep 21, 2026 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.28.4, PUT /@warpgate/admin/api/users/... |
| CVE-2026-91166 | MEDIUM | 5.7 | 0.3% | Sep 21, 2026 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.25.0 until 0.27.6, the browser SSH path i... |
| CVE-2026-91164 | MEDIUM | 4.3 | 0.4% | Sep 21, 2026 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. From 0.23.0 until 0.27.3, HTTP API token authent... |
| CVE-2026-82165 | MEDIUM | 5.5 | 0.1% | Sep 21, 2026 | Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions vu... |
| CVE-2026-82163 | MEDIUM | 5.5 | 0.1% | Sep 21, 2026 | Dell Command | Intel vPro Out of Band, versions prior to 4.7.2, contain an Incorrect Default Permissions vulnerability. ... |
| CVE-2026-63329 | MEDIUM | 4.9 | 0.3% | Sep 21, 2026 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.6, copy_server_request in warpgate... |
| CVE-2026-61749 | MEDIUM | 6.5 | 0.5% | Sep 21, 2026 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, privileged staff users who can author report or... |
| CVE-2026-61748 | MEDIUM | 4.3 | 0.4% | Sep 21, 2026 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, ReportPrint at POST /api/report/print/ and Labe... |
| CVE-2026-61747 | MEDIUM | 4.3 | 0.3% | Sep 21, 2026 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the /api/importer/row/ and /api/importer/mappin... |
| CVE-2026-61746 | MEDIUM | 5.3 | 0.4% | Sep 21, 2026 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, PluginSettingList, PluginAllSettingList, and Pl... |
| CVE-2026-61744 | MEDIUM | 6.5 | 0.4% | Sep 21, 2026 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, POST /api/barcode/ accepts an attacker-synthesi... |
| CVE-2026-92382 | MEDIUM | 4.1 | 0.1% | Sep 21, 2026 | An out-of-bounds write flaw was found in usbredir. Starting an isochronous OUT stream with a transfer count of 1 leaves ... |
| CVE-2026-69190 | MEDIUM | 6.3 | 0.4% | Sep 21, 2026 | Graylog is a free and open log management platform. From 6.3.0 until 6.3.14, 7.0.9, and 7.1.4, the view update API for s... |
| CVE-2026-61745 | MEDIUM | 4.3 | 0.3% | Sep 21, 2026 | InvenTree is an Open Source Inventory Management System. Prior to 1.4.0, the POST /api/machine/{pk}/restart/ endpoint in... |
| CVE-2026-61612 | MEDIUM | 5.7 | 0.2% | Sep 21, 2026 | CKAN MCP Server is a tool for querying CKAN open data portals. Prior to version 0.4.108, the SSRF guard `validateServerU... |
| CVE-2026-55473 | MEDIUM | 6 | 0.2% | Sep 21, 2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, the default-on BlockBogonNets and BlockCloudMetada... |
| CVE-2026-48974 | MEDIUM | 5.4 | 0.2% | Sep 21, 2026 | HomeBox is a home inventory and organization system. Prior to 0.26.0, POST /v1/groups/members invokes HandleGroupMemberA... |
| CVE-2026-77582 | MEDIUM | 6.9 | 0.4% | Sep 21, 2026 | Tinyauth is an authentication and authorization server. Prior to 5.1.0, Tinyauth exposes a remotely observable timing di... |
| CVE-2026-77561 | MEDIUM | 5.3 | 0.9% | Sep 21, 2026 | Tinyauth is an authentication and authorization server. Prior to 5.1.0, an unauthenticated remote attacker can send POST... |
| CVE-2026-63373 | MEDIUM | 4.2 | 0.1% | Sep 21, 2026 | draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, the OAuth callback handler... |
| CVE-2026-63334 | MEDIUM | 6.8 | 0.2% | Sep 21, 2026 | draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, deployments with ENABLE_DR... |
| CVE-2026-62987 | MEDIUM | 5.8 | 0.2% | Sep 21, 2026 | Fabio is an HTTP(S) and TCP router for deploying applications managed by consul. From 1.6.6 until 1.7.2, the CVE-2025-48... |
| CVE-2026-62866 | MEDIUM | 6.2 | 0.2% | Sep 21, 2026 | Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1... |
| CVE-2026-62370 | MEDIUM | 6.5 | 0.9% | Sep 21, 2026 | KubeEdge is an open source system for extending native containerized application orchestration capabilities to hosts at ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now