2026 CVE Vulnerabilities
64,772 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-63342 | MEDIUM | 6.3 | 0.2% | Sep 21, 2026 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, ap... |
| CVE-2026-61681 | MEDIUM | 4.1 | 0.3% | Sep 21, 2026 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.91.1, th... |
| CVE-2026-36472 | MEDIUM | 5.2 | 0.2% | Sep 21, 2026 | CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS). Improper neutralization of the __referer value 2.0.1 allow... |
| CVE-2026-36471 | MEDIUM | 5.8 | 0.3% | Sep 21, 2026 | Deserialization of Untrusted Data of the __post_data parameter in cn_parse_url() in CuteNews v.2.1.2 allows a remote att... |
| CVE-2026-36470 | MEDIUM | 5.8 | 0.1% | Sep 21, 2026 | CuteNews v.2.1.2 is vulnerable to Cross Site Scripting (XSS) in index.php. The value of the "Referer" header is copied i... |
| CVE-2026-36468 | MEDIUM | 6.1 | 0.2% | Sep 21, 2026 | Cross-site Scripting (XSS) in index.php in CuteNews v.2.1.2 allows remote unauthenticated attackers to supply an arbitra... |
| CVE-2026-93339 | MEDIUM | 5.4 | 0.3% | Sep 21, 2026 | Metaphor Creations Ditty (ditty-news-ticker) before 3.1.70 contains a stored cross-site scripting vulnerability that all... |
| CVE-2026-82355 | MEDIUM | 4.2 | 0.3% | Sep 21, 2026 | When a request to the Airflow core API carries both a session cookie and an explicit `Authorization: Bearer` token, Airf... |
| CVE-2026-75158 | MEDIUM | 4.3 | 0.4% | Sep 21, 2026 | Apache Airflow's `/assets/events` API returned asset events for every Dag in the deployment, with no filter restricting ... |
| CVE-2026-61630 | MEDIUM | 4.2 | 0.4% | Sep 21, 2026 | nginx ignition is a user interface for the nginx web server. In versions 2.33.0 through 2.35.0, any user that has enable... |
| CVE-2026-55625 | MEDIUM | 4.9 | 0.5% | Sep 21, 2026 | GoCD is a continuous deliver server. From 16.1.0 until 26.1.0, the internal material connection test APIs at /go/api/adm... |
| CVE-2026-54584 | MEDIUM | 5.3 | 0.5% | Sep 21, 2026 | mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including w... |
| CVE-2026-52743 | MEDIUM | 4.3 | 0.3% | Sep 21, 2026 | GoCD is a continuous deliver server. Prior to 26.1.0, the internal GoCD UI /jobStatus.json API does not validate that a ... |
| CVE-2026-52742 | MEDIUM | 5.1 | 0.5% | Sep 21, 2026 | GoCD is a continuous deliver server. From 12.3.1 until 26.1.0, legacy routes under /go/admin/restful/* expose historical... |
| CVE-2026-52740 | MEDIUM | 5.3 | 0.4% | Sep 21, 2026 | GoCD is a continuous deliver server. From 18.7.0 until 26.1.0, the Get Template Config API compares HTTP method names ca... |
| CVE-2026-94394 | MEDIUM | 6.3 | — | Sep 21, 2026 | When a regular user adds a reference between objects or attributes, MISP checks whether the user can access the overall ... |
| CVE-2026-94393 | MEDIUM | 6.4 | — | Sep 21, 2026 | When a user creates or edits a report inside an event, MISP can identify an existing report using its UUID without prope... |
| CVE-2026-94387 | MEDIUM | 5.4 | 0.3% | Sep 21, 2026 | Aureus ERP before 1.6.0 contains a stored cross-site scripting vulnerability in the Chatter field-change log where old_v... |
| CVE-2026-94382 | MEDIUM | 4.2 | 0.2% | Sep 21, 2026 | Beszel before 0.19.0 contains an insecure direct object reference vulnerability in the POST and DELETE /api/beszel/user-... |
| CVE-2026-94379 | MEDIUM | 6.9 | — | Sep 21, 2026 | The login() function in MISP's UsersController.php contained insufficient HTTP method validation for several security-cr... |
| CVE-2026-94373 | MEDIUM | 6.3 | — | Sep 21, 2026 | MISP contains a DOM-based cross-site scripting (XSS) vulnerability in the contextual menu JavaScript component. The Cont... |
| CVE-2026-94372 | MEDIUM | 6.3 | — | Sep 21, 2026 | MISP contains a stored cross-site scripting (XSS) vulnerability in the default theme's Galaxies index page. When a MISP ... |
| CVE-2026-94216 | MEDIUM | 4.3 | — | Sep 21, 2026 | A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This... |
| CVE-2026-94214 | MEDIUM | 4.3 | 0.3% | Sep 21, 2026 | A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affe... |
| CVE-2026-91867 | MEDIUM | 4.3 | 0.3% | Sep 21, 2026 | When Neethi fetches a remote policy reference, it only limits the time per read, not the whole transfer, so a server tha... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now