2026 CVE Vulnerabilities
64,779 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54355 | MEDIUM | 5.3 | 0.7% | Sep 17, 2026 | MapServer is a system for developing web-based GIS applications. From 6.0 until 8.6.4, MapServer's OpenLayers HTML outpu... |
| CVE-2026-50022 | MEDIUM | 5.8 | 0.3% | Sep 17, 2026 | Metacat is data repository software that helps researchers preserve, share, and discover data. Prior to 3.4.2, MetacatSo... |
| CVE-2026-92993 | MEDIUM | 6.3 | 1.5% | Sep 17, 2026 | A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of... |
| CVE-2026-92758 | MEDIUM | 5.5 | 0.2% | Sep 17, 2026 | If logging mode is set to DEBUG or a malformed MongoDB connection string is used, application logs may collect sensitive... |
| CVE-2026-92757 | MEDIUM | 5.5 | 0.1% | Sep 17, 2026 | Applications built on MongoDB Entity Framework Core Provider which place a database name in the connection string may in... |
| CVE-2026-92756 | MEDIUM | 5.5 | 0.1% | Sep 17, 2026 | Applications built on MongoDB Entity Framework Core Provider which combine independent encryption settings and this prov... |
| CVE-2026-54594 | MEDIUM | 5.3 | 0.3% | Sep 17, 2026 | OmniBlocks is a monorepo for the OmniBlocks project. Prior to the June 6, 2026 workflow remediation, .github/workflows/d... |
| CVE-2026-54495 | MEDIUM | 4.3 | 0.3% | Sep 17, 2026 | The OpenFeature Operator allows users to expose feature flags to applications. In version 0.9.2 and earlier, a tenant wh... |
| CVE-2026-92992 | MEDIUM | 6.3 | — | Sep 17, 2026 | A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown functio... |
| CVE-2026-52852 | MEDIUM | 6.5 | 0.5% | Sep 17, 2026 | Traccar is an open source GPS tracking system. Prior to 6.14.0, an authenticated user with permission to manage groups a... |
| CVE-2026-92927 | MEDIUM | 5.3 | 0.3% | Sep 17, 2026 | A vulnerability was found in SourceCodester Drug Recommendation System 1.0. This issue affects some unknown processing o... |
| CVE-2026-89038 | MEDIUM | 6.2 | 0.1% | Sep 17, 2026 | Verizon Cloud for Android (com.vcast.mediamanager) before 26.7.10 contains a path traversal vulnerability that allows co... |
| CVE-2026-54677 | MEDIUM | 6.5 | 0.4% | Sep 17, 2026 | Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, authenticated users who are not members of ... |
| CVE-2026-54676 | MEDIUM | 6.5 | 0.4% | Sep 17, 2026 | Scoold is a Q&A and a knowledge sharing platform for teams. Prior to 1.69.0, users with personal API tokens can retrieve... |
| CVE-2026-54551 | MEDIUM | 4.3 | 0.4% | Sep 17, 2026 | WireGuard Portal, or wg-portal, is a web-based configuration portal for WireGuard server management. From 2.2.0 until 2.... |
| CVE-2026-54546 | MEDIUM | 5 | — | Sep 17, 2026 | CloudTAK is a browser-based Common Operating Picture and situational awareness tool compatible with TAK. Prior to 13.22.... |
| CVE-2026-44235 | MEDIUM | 6.5 | — | Sep 17, 2026 | rabbitmq-c is a C-language AMQP client library for RabbitMQ. Prior to 0.16.0, a malicious AMQP server can send an unders... |
| CVE-2026-8674 | MEDIUM | 5.3 | — | Sep 17, 2026 | Initializing the DNS stub resolver from an /etc/resolv.conf file, or a LOCALDOMAIN environment variable, whose search li... |
| CVE-2026-85720 | MEDIUM | 5.9 | 0.3% | Sep 17, 2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT... |
| CVE-2026-54587 | MEDIUM | 5.8 | — | Sep 17, 2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets handled as ASSET_DIR or ASSET_DIR_OWNER_MODE ... |
| CVE-2026-54586 | MEDIUM | 6 | 0.1% | Sep 17, 2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, the mport_fetch_index(), mport_fetch_bootstrap_index(), and mp... |
| CVE-2026-54585 | MEDIUM | 6 | — | Sep 17, 2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c did... |
| CVE-2026-54582 | MEDIUM | 6 | — | Sep 17, 2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, package installation lacked a preflight check for incoming non... |
| CVE-2026-54576 | MEDIUM | 5.8 | — | Sep 17, 2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c used... |
| CVE-2026-54575 | MEDIUM | 5.8 | 0.1% | Sep 17, 2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged package fetch and cache-cleaning operations used ra... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now