2026 CVE Vulnerabilities
64,766 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59168 | MEDIUM | 6.2 | 0.1% | Sep 21, 2026 | Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.1... |
| CVE-2026-58504 | MEDIUM | 6.1 | 0.2% | Sep 21, 2026 | draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.5, opening or importing a cra... |
| CVE-2026-17051 | MEDIUM | 6 | 0.1% | Sep 21, 2026 | The Intel SEDI IPM (inter-processor mailbox) driver in drivers/ipm/ipm_sedi.c handles an inbound message interrupt in ip... |
| CVE-2026-17050 | MEDIUM | 5.7 | 0.2% | Sep 21, 2026 | The experimental USB host stack allocates a per-device configuration-descriptor buffer, udev->cfg_desc, from the dedicat... |
| CVE-2026-88978 | MEDIUM | 4.3 | 0.3% | Sep 21, 2026 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.106.1, t... |
| CVE-2026-77165 | MEDIUM | 6.5 | 0.3% | Sep 21, 2026 | File owners were unable to unlock TYPE_TOKEN locks placed by other users, leaving files permanently locked with no recov... |
| CVE-2026-63342 | MEDIUM | 6.3 | 0.2% | Sep 21, 2026 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ap... |
| CVE-2026-61681 | MEDIUM | 4.1 | 0.3% | Sep 21, 2026 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, th... |
| CVE-2026-36472 | MEDIUM | 5.2 | 0.2% | Sep 21, 2026 | CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutralization of the __referer value 2.0.1 allow... |
| CVE-2026-36471 | MEDIUM | 5.8 | 0.3% | Sep 21, 2026 | Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote att... |
| CVE-2026-36470 | MEDIUM | 5.8 | 0.1% | Sep 21, 2026 | CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php. The value of the "Referer" header is copied i... |
| CVE-2026-36468 | MEDIUM | 6.1 | 0.2% | Sep 21, 2026 | Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an arbitra... |
| CVE-2026-93339 | MEDIUM | 5.4 | 0.3% | Sep 21, 2026 | Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that all... |
| CVE-2026-82355 | MEDIUM | 4.2 | 0.3% | Sep 21, 2026 | When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airf... |
| CVE-2026-75158 | MEDIUM | 4.3 | 0.4% | Sep 21, 2026 | Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting ... |
| CVE-2026-61630 | MEDIUM | 4.2 | 0.4% | Sep 21, 2026 | nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enable... |
| CVE-2026-55625 | MEDIUM | 4.9 | 0.5% | Sep 21, 2026 | GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /go/api/adm... |
| CVE-2026-54584 | MEDIUM | 5.3 | 0.5% | Sep 21, 2026 | mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including w... |
| CVE-2026-52743 | MEDIUM | 4.3 | 0.3% | Sep 21, 2026 | GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a ... |
| CVE-2026-52742 | MEDIUM | 5.1 | 0.5% | Sep 21, 2026 | GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical... |
| CVE-2026-52740 | MEDIUM | 5.3 | 0.4% | Sep 21, 2026 | GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP method names ca... |
| CVE-2026-94394 | MEDIUM | 6.3 | — | Sep 21, 2026 | When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall ... |
| CVE-2026-94393 | MEDIUM | 6.4 | — | Sep 21, 2026 | When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without prope... |
| CVE-2026-94387 | MEDIUM | 5.4 | 0.3% | Sep 21, 2026 | Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_v... |
| CVE-2026-94382 | MEDIUM | 4.2 | 0.2% | Sep 21, 2026 | Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now