2026 CVE Vulnerabilities
65,524 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100699 | MEDIUM | 5.3 | — | Sep 26, 2026 | Nodemailer is a Node.js email-sending library. In versions >= 9.1.0 and < 10.0.9, the address parser (src/addressparser)... |
| CVE-2026-100698 | MEDIUM | 5.8 | — | Sep 26, 2026 | Adminer 5.5.1 through 6.0.1 improperly parses the login 'server' string in the host_port() function in adminer/include/f... |
| CVE-2026-100697 | HIGH | 8.6 | — | Sep 26, 2026 | Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.... |
| CVE-2026-100696 | MEDIUM | 5.8 | — | Sep 26, 2026 | Adminer 4.16.0 through 6.0.1 contain a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the option... |
| CVE-2026-100695 | MEDIUM | 6.1 | — | Sep 26, 2026 | Adminer before 6.0.2 contains a cross-site scripting vulnerability where the CONNECTION_ID() database result is interpol... |
| CVE-2026-100694 | MEDIUM | 6.1 | 0.2% | Sep 26, 2026 | Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media t... |
| CVE-2026-100693 | HIGH | 8.4 | 0.1% | Sep 26, 2026 | Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-litera... |
| CVE-2026-100692 | HIGH | 7.5 | 0.4% | Sep 26, 2026 | Hugo is a static site generator. In versions after v0.123.0 and before v0.166.0, Hugo's symlink confinement checks stopp... |
| CVE-2026-100691 | MEDIUM | 5.4 | 0.2% | Sep 26, 2026 | Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does no... |
| CVE-2026-100690 | HIGH | 7.5 | 0.3% | Sep 26, 2026 | Hugo versions from v0.161.0 through v0.165.0 run Node.js tools (css.PostCSS, css.TailwindCSS, js.Babel) under the Node.j... |
| CVE-2026-100689 | MEDIUM | 5.9 | — | Sep 26, 2026 | GitPython before 3.1.62 does not validate the `path` field read from an untrusted .gitmodules file when updating submodu... |
| CVE-2026-100688 | MEDIUM | 6.5 | — | Sep 26, 2026 | Budibase server before 3.45.0 contains a cross-tenant information disclosure vulnerability in the GET /api/applications/... |
| CVE-2026-100687 | MEDIUM | 5.5 | — | Sep 26, 2026 | Budibase Server before 3.45.0 fails to redact plaintext datasource credentials before broadcasting external table update... |
| CVE-2026-100686 | HIGH | 8.1 | — | Sep 26, 2026 | Budibase versions before 3.45.0 fail to validate per-app authorization in the POST /api/global/groups/:groupId/apps endp... |
| CVE-2026-100685 | HIGH | 7.7 | — | Sep 26, 2026 | Budibase before 3.45.0 fails to properly scope the GET /api/chat-links endpoint by workspace, allowing builders to enume... |
| CVE-2026-100684 | HIGH | 8.1 | — | Sep 26, 2026 | Budibase versions 3.41.0 before 3.45.0 contain an authentication bypass in the OIDC/SSO login path of @budibase/server. ... |
| CVE-2026-100683 | HIGH | 8 | — | Sep 26, 2026 | Budibase (@budibase/server) before 3.45.0 builds MySQL and MSSQL column-rename DDL in packages/backend-core/src/sql/sqlT... |
| CVE-2026-100682 | HIGH | 8.8 | — | Sep 26, 2026 | Budibase Server before 3.45.0 contains an arbitrary file write vulnerability in the PWA icon upload endpoint that extrac... |
| CVE-2026-100681 | MEDIUM | 5.4 | — | Sep 26, 2026 | Budibase before 3.45.0 contains an unauthenticated server-side request forgery and credential exfiltration vulnerability... |
| CVE-2026-100680 | HIGH | 8.1 | — | Sep 26, 2026 | Budibase versions before 3.45.0 fail to disable external JSON reference resolution in the OpenAPI/Swagger import validat... |
| CVE-2026-100679 | HIGH | 8.8 | — | Sep 26, 2026 | stoatchat before 0.15.5 fails to validate that MFA tickets belong to the authenticated user, allowing attackers to bypas... |
| CVE-2026-100678 | MEDIUM | 6.5 | — | Sep 26, 2026 | stoatchat before 0.15.5 fails to enforce account-level attempt limits on MFA login challenges, allowing attackers who kn... |
| CVE-2026-100677 | MEDIUM | 5.3 | — | Sep 26, 2026 | stoatchat before 0.15.5 contains an account enumeration vulnerability in the login endpoint that exposes source file loc... |
| CVE-2026-100676 | HIGH | 8.2 | — | Sep 26, 2026 | January, the media proxy/embed service of stoatchat (stoatchat/stoatchat), before version 0.15.5 improperly resolves SVG... |
| CVE-2026-100675 | MEDIUM | 6.5 | — | Sep 26, 2026 | stoatchat versions before 0.15.5 contain a denial of service vulnerability in the acknowledgement worker that processes ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now