2026 CVE Vulnerabilities
64,772 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-94047 | MEDIUM | 6.3 | 0.4% | Sep 20, 2026 | A security vulnerability has been detected in samanhappy MCPHub up to 1.0.32. The impacted element is the function impor... |
| CVE-2026-94046 | MEDIUM | 4.3 | 0.4% | Sep 20, 2026 | A weakness has been identified in 0215AndrewFeng ACE-MCP up to 4.10.8. The affected element is the function get_file_sni... |
| CVE-2026-94043 | MEDIUM | 5.3 | 0.3% | Sep 20, 2026 | A vulnerability was determined in Free5GC up to 4.2.3. This vulnerability affects unknown code of the file /corefuzzer_d... |
| CVE-2026-94042 | MEDIUM | 6.3 | 0.2% | Sep 20, 2026 | A vulnerability was found in AdithyaYelloju Restaurant Management System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff6b9c.... |
| CVE-2026-94041 | MEDIUM | 6.3 | 0.2% | Sep 20, 2026 | A vulnerability has been found in AdithyaYelloju Restaurant-Management-System up to 7f0e7e84255e8fcfd488e83f8f91451bbbff... |
| CVE-2026-94040 | MEDIUM | 5.3 | 0.3% | Sep 20, 2026 | A flaw has been found in vas3k TaxHacker up to 0.8.5. Affected by this vulnerability is the function testLLMProviderActi... |
| CVE-2026-94037 | MEDIUM | 4.3 | 0.3% | Sep 20, 2026 | A weakness has been identified in 00Kisumi00 mcp-file-analyzer up to 84740852f0cf0cf5db4781b1ca6d7c6a6d210405. This affe... |
| CVE-2026-94035 | MEDIUM | 4.3 | 0.3% | Sep 20, 2026 | A vulnerability was determined in SourceCodester Drug Recommendation System 1.0. Impacted is an unknown function of the ... |
| CVE-2026-94032 | MEDIUM | 6.3 | 0.2% | Sep 20, 2026 | A flaw has been found in itsourcecode Leave Management System 1.0. This affects an unknown part of the file /module/depa... |
| CVE-2026-94031 | MEDIUM | 6.3 | 1.1% | Sep 20, 2026 | A vulnerability was detected in 0-Gaurav-0 nexus-mcp aed0026e7ac1f23dc940e46e9fd3a2da6904f914. Affected by this issue is... |
| CVE-2026-94028 | MEDIUM | 4.3 | 0.4% | Sep 20, 2026 | A weakness has been identified in mealie-recipes Mealie up to 3.25.1. Affected is the function payload.model_dump of the... |
| CVE-2026-92254 | MEDIUM | 6.9 | 0.1% | Sep 20, 2026 | Missing Authorization in the IOCTL handlers of the wsdkd.sys kernel drivers in Watchdog WatchDog Antivirus 1.8.640 (driv... |
| CVE-2026-92253 | MEDIUM | 5.2 | 0.1% | Sep 20, 2026 | Improper link resolution before file access in the quarantine restoration process of WatchDog Anti-Virus 1.8.640 on Wind... |
| CVE-2026-92252 | MEDIUM | 5.9 | 0.1% | Sep 20, 2026 | Incorrect default permissions in the installation directory of WatchDog Anti-Virus on Windows allow local, low-privilege... |
| CVE-2026-94113 | MEDIUM | 6.5 | 0.2% | Sep 20, 2026 | Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contain an information disclosure vulnerability in white... |
| CVE-2026-94112 | MEDIUM | 6.8 | 0.4% | Sep 20, 2026 | mayswind ezBookkeeping before 2.0.0 fails to invalidate TOTP passcodes after use, allowing attackers to replay captured ... |
| CVE-2026-94111 | MEDIUM | 6.6 | 0.1% | Sep 20, 2026 | Tencent BrowserSkill through 0.3.0 contains an authentication bypass vulnerability in the local daemon WebSocket origin ... |
| CVE-2026-94108 | MEDIUM | 6.5 | 0.4% | Sep 20, 2026 | getID3 through 1.9.26 contains an XML external entity injection vulnerability in the XML2array helper function that fail... |
| CVE-2026-94105 | MEDIUM | 5.3 | 0.3% | Sep 20, 2026 | NivoCart through 2.4.0 contains a destructive configuration write vulnerability in the admin password reset controller t... |
| CVE-2026-86555 | MEDIUM | 6.2 | 0.2% | Sep 20, 2026 | The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plain... |
| CVE-2026-93971 | MEDIUM | 5.3 | 0.3% | Sep 20, 2026 | A weakness has been identified in aiyiyi121 SxDevOps 1.0/1.1. Impacted is an unknown function of the file backend/sxdevo... |
| CVE-2026-86554 | MEDIUM | 4.3 | 0.2% | Sep 20, 2026 | SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process... |
| CVE-2026-93967 | MEDIUM | 5.5 | 0.7% | Sep 20, 2026 | A vulnerability was found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this issue is the function generate_host_task of th... |
| CVE-2026-93966 | MEDIUM | 4.7 | 1.6% | Sep 20, 2026 | A vulnerability has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this vulnerability is the function paramiko.SS... |
| CVE-2026-92422 | MEDIUM | 6.5 | 0.1% | Sep 20, 2026 | The Meow Gallery WordPress plugin before 5.5.5 does not properly sanitize a user-supplied value before concatenating it ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now