2026 CVE Vulnerabilities
64,766 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-79316 | HIGH | 7.6 | 0.2% | Sep 21, 2026 | An improper access control vulnerability exists in x-ui 0.3.2. Any authenticated panel user can modify the xray configur... |
| CVE-2026-77523 | HIGH | 7.4 | — | Sep 21, 2026 | MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the model parameter form route a... |
| CVE-2026-73553 | HIGH | 7.5 | 0.5% | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-61647 | HIGH | 7.1 | 0.3% | Sep 21, 2026 | NotebookLM MCP is an MCP server and HTTP service for interacting with Google NotebookLM and exporting generated content ... |
| CVE-2026-55105 | HIGH | 7.7 | 0.4% | Sep 21, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.1... |
| CVE-2026-49453 | HIGH | 7 | 0.3% | Sep 21, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.6.1... |
| CVE-2026-49450 | HIGH | 7.1 | 0.1% | Sep 21, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Prior to 3.7.2... |
| CVE-2026-81469 | HIGH | 7.8 | 0.2% | Sep 21, 2026 | Dell Inventory Collector Client, versions prior to 15.0.0, contain an Unquoted Search Path or Element vulnerability. A l... |
| CVE-2026-73552 | HIGH | 7.5 | 0.7% | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-73550 | HIGH | 7.5 | 0.9% | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-73548 | HIGH | 7.5 | 0.7% | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-73547 | HIGH | 7.5 | 0.8% | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-73546 | HIGH | 7.4 | 0.6% | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-73513 | HIGH | 7.5 | 0.7% | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-73512 | HIGH | 7.5 | 0.8% | Sep 21, 2026 | Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.36.10, 1.37.6, 1.38.4,... |
| CVE-2026-58269 | HIGH | 8.1 | 0.2% | Sep 21, 2026 | Sync-in Server is an open-source platform for file storage, sharing, collaboration, and syncing. Prior to version 2.4.0,... |
| CVE-2026-55897 | HIGH | 8.8 | 0.7% | Sep 21, 2026 | luci-app-advanced-reboot is a LuCI (web interface) application for OpenWrt that provides a way to reboot your router in... |
| CVE-2026-55159 | HIGH | 8.8 | 1.0% | Sep 21, 2026 | luci-app-adblock-fast a WebUI for fast, lightweight DNS-based ad-blocker for OpenWrt that works with dnsmasq, smartdns, ... |
| CVE-2026-52835 | HIGH | 7 | — | Sep 21, 2026 | Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the import_config handle... |
| CVE-2026-49811 | HIGH | 8.4 | 0.1% | Sep 21, 2026 | Dell Command | Monitor (DCM), versions prior to 10.13.2, contain an Incorrect Permission Assignment for Critical Resourc... |
| CVE-2026-94501 | HIGH | 8.8 | 0.3% | Sep 21, 2026 | jshERP through 3.6 contains an authorization bypass vulnerability in the userBusiness CRUD endpoints that allows authent... |
| CVE-2026-94497 | HIGH | 8.3 | 0.3% | Sep 21, 2026 | jshERP through 3.6 fails to validate object ownership in by-id info, update, and delete endpoints across multiple resour... |
| CVE-2026-94496 | HIGH | 8.3 | 0.3% | Sep 21, 2026 | jshERP through 3.6 fails to validate caller permissions in role management endpoints, allowing authenticated users to mo... |
| CVE-2026-94495 | HIGH | 7.1 | 0.4% | Sep 21, 2026 | jshERP through 3.6 fails to properly validate user privileges in SystemConfigService.updateSystemConfig, allowing authen... |
| CVE-2026-94412 | HIGH | 8.8 | 0.3% | Sep 21, 2026 | jshERP through 3.6 contains an authorization bypass vulnerability in the POST /user/resetPwd endpoint that allows authen... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now