2026 CVE Vulnerabilities
65,537 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100612 | HIGH | 7.2 | — | Sep 26, 2026 | Capgo (capgo.app) through version 12.261.0 contains an incomplete access-control fix for the public.sso_providers table.... |
| CVE-2026-100611 | MEDIUM | 6.5 | — | Sep 26, 2026 | Capgo (capgo.app backend, versions ≤ 12.261.0) improperly restricts which roles the apikey_manager organization role may... |
| CVE-2026-100610 | HIGH | 7.5 | — | Sep 26, 2026 | Flowise through 3.1.4 exposes GET /api/v1/upsert-history/:id and PATCH /api/v1/upsert-history without route-level permis... |
| CVE-2026-100609 | MEDIUM | 6.8 | — | Sep 26, 2026 | Flowise (npm packages `flowise` and `flowise-components`) through 3.1.4 looks up credentials by ID without filtering on ... |
| CVE-2026-100608 | HIGH | 8.3 | — | Sep 26, 2026 | Flowise through 3.1.4 does not enforce authorization on the BullMQ admin dashboard. When the server runs in queue mode w... |
| CVE-2026-100607 | HIGH | 7.7 | — | Sep 26, 2026 | Flowise through 3.1.4 resolves SSO and local-password users solely by email without storing provider or subject identifi... |
| CVE-2026-100606 | HIGH | 7.7 | — | Sep 26, 2026 | Flowise through 3.1.4 (Enterprise/platform mode with SSO enabled) contains an authentication bypass in the SSO login pat... |
| CVE-2026-100605 | HIGH | 7.1 | — | Sep 26, 2026 | Flowise through 3.1.4 contains missing route-level RBAC checks on chat message endpoints that allow low-privileged API k... |
| CVE-2026-100604 | MEDIUM | 5.4 | — | Sep 26, 2026 | ClawHub (openclaw/clawhub) contains an incorrect authorization vulnerability in the ClawHub application/backend: an orga... |
| CVE-2026-100603 | MEDIUM | 5.4 | — | Sep 26, 2026 | ClawHub (openclaw/clawhub) application/backend contains a flaw in the skill report moderation flow: four distinct ordina... |
| CVE-2026-100602 | MEDIUM | 6.5 | — | Sep 26, 2026 | ClawHub (openclaw/clawhub application/backend) contains a missing authorization check in the changelog preview feature. ... |
| CVE-2026-100601 | MEDIUM | 5.3 | — | Sep 26, 2026 | ClawHub (openclaw/clawhub) application/backend contains a server-side request forgery vulnerability in the public profil... |
| CVE-2026-100600 | MEDIUM | 5.3 | — | Sep 26, 2026 | ClawHub (the openclaw/clawhub application/backend) does not bind anonymous HTTP API requests to a trusted caller identit... |
| CVE-2026-100315 | HIGH | 7.3 | — | Sep 26, 2026 | A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. ... |
| CVE-2026-100314 | HIGH | 7.3 | — | Sep 26, 2026 | A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db... |
| CVE-2026-100313 | MEDIUM | 4.3 | — | Sep 26, 2026 | A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be... |
| CVE-2026-98163 | — | — | — | Sep 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: cgroup: Avoid iteration of dying tasks with zero re... |
| CVE-2026-100312 | MEDIUM | 6.3 | — | Sep 26, 2026 | A security flaw has been discovered in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b6... |
| CVE-2026-100311 | LOW | 3.5 | — | Sep 26, 2026 | A vulnerability was identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be... |
| CVE-2026-96533 | MEDIUM | 5.8 | — | Sep 26, 2026 | The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-s... |
| CVE-2026-96532 | HIGH | 7.5 | — | Sep 26, 2026 | The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling it... |
| CVE-2026-96531 | MEDIUM | 6.8 | — | Sep 26, 2026 | The Optimole WordPress plugin before 4.2.13 does not escape unrecognized attributes of its video-player block before re... |
| CVE-2026-96526 | LOW | 2.7 | — | Sep 26, 2026 | The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an object-level authorization check on one ... |
| CVE-2026-96525 | LOW | 2.7 | — | Sep 26, 2026 | The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an ownership or sufficient capability check... |
| CVE-2026-96524 | HIGH | 8.8 | — | Sep 26, 2026 | The MCP Server for WordPress WordPress plugin before 1.8.2 does not correctly verify the WordPress REST API nonce for c... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now