2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-64684 | MEDIUM | 6.8 | 0.4% | Sep 16, 2026 | RMCP is an official Rust SDK for the Model Context Protocol. Prior to 2.1.0, the rmcp crate's StreamableHttpClientTransp... |
| CVE-2026-61597 | MEDIUM | 5.1 | — | Sep 16, 2026 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to ... |
| CVE-2026-92814 | MEDIUM | 4.2 | 0.2% | Sep 16, 2026 | changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary marku... |
| CVE-2026-92813 | MEDIUM | 4.9 | 0.3% | Sep 16, 2026 | Metabase through 0.63.18 fails to properly validate the unspecified address 0.0.0.0 in custom GeoJSON URLs, allowing una... |
| CVE-2026-92812 | MEDIUM | 6.8 | 0.3% | Sep 16, 2026 | decap-server contains a path traversal vulnerability in the local proxy containment guard that uses plain string prefix ... |
| CVE-2026-92811 | MEDIUM | 6.5 | 0.3% | Sep 16, 2026 | browserless versions 1.44.0 through 2.56.7 fail to enforce file protocol restrictions in Playwright websocket endpoints,... |
| CVE-2026-92810 | MEDIUM | 4.3 | 0.2% | Sep 16, 2026 | PrestaShop blockwishlist through 3.0.2 fails to validate wishlist ownership in the getUrlByIdWishListAction method, allo... |
| CVE-2026-92809 | MEDIUM | 4.3 | 0.2% | Sep 16, 2026 | PrestaShop psgdpr versions through 1.4.3 fail to validate that GDPR consent log entries are attributed to the authentica... |
| CVE-2026-92803 | MEDIUM | 5.3 | 0.4% | Sep 16, 2026 | LibreTranslate through 1.9.6 omits the access_check decorator from the download_file route, allowing unauthenticated acc... |
| CVE-2026-92802 | MEDIUM | 4.3 | 0.2% | Sep 16, 2026 | kan through 0.6.0 fails to properly validate board creation permissions in the GitHub project import endpoint, allowing ... |
| CVE-2026-92800 | MEDIUM | 6.8 | 0.2% | Sep 16, 2026 | Docs before 5.4.1 fails to properly revoke websocket collaboration connections when access is revoked at parent document... |
| CVE-2026-92795 | MEDIUM | 6.5 | 0.4% | Sep 16, 2026 | Coze Studio through 0.5.1 fails to restrict the server URL supplied when registering plugin tools, allowing authenticate... |
| CVE-2026-92790 | MEDIUM | 6.5 | 0.5% | Sep 16, 2026 | Higress before 2.2.4 panics when processing a Cookie header segment without an equals sign, causing the plugin wrapper t... |
| CVE-2026-92789 | MEDIUM | 6.5 | 0.3% | Sep 16, 2026 | Graylog through 7.1.4 validates outbound URLs against an allowlist before making requests but fails to re-validate after... |
| CVE-2026-92781 | MEDIUM | 6.3 | 0.4% | Sep 16, 2026 | Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the unflatten he... |
| CVE-2026-92778 | MEDIUM | 5.4 | 0.3% | Sep 16, 2026 | CMAK through 3.0.0.6 fails to apply the scheduled leader election feature toggle to HTML form routes, allowing attackers... |
| CVE-2026-92775 | MEDIUM | 6.5 | 0.4% | Sep 16, 2026 | Wiki.js through 2.5.314 contains a server-side request forgery vulnerability in the Image Prefetch renderer that fetches... |
| CVE-2026-92774 | MEDIUM | 4.3 | 0.4% | Sep 16, 2026 | Wiki.js through 2.5.314 omits page tags from authorization checks in multiple GraphQL resolvers, allowing tag-based acce... |
| CVE-2026-92771 | MEDIUM | 6.5 | 0.3% | Sep 16, 2026 | Twenty before 2.35.0 fails to validate field and row permissions in the groupBy-with-records GraphQL resolver, allowing ... |
| CVE-2026-92770 | MEDIUM | 6.5 | 0.5% | Sep 16, 2026 | Harbor through 2.15.2 fails to properly restrict the q query parameter filtering on scanner registration access credenti... |
| CVE-2026-92765 | MEDIUM | 6.5 | 0.5% | Sep 16, 2026 | ArcherySec through 2.0.6 fails to validate organization ownership in the WebScanVulnList endpoint, allowing authenticate... |
| CVE-2026-92764 | MEDIUM | 4.3 | 0.3% | Sep 16, 2026 | OpenCVE versions 2.4.0 before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, ... |
| CVE-2026-92760 | MEDIUM | 6.5 | 0.4% | Sep 16, 2026 | Shlink through 5.1.6 fails to enforce API key role restrictions when issuing Mercure subscription tokens, allowing restr... |
| CVE-2026-92759 | MEDIUM | 6.5 | 0.5% | Sep 16, 2026 | SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that... |
| CVE-2026-92754 | MEDIUM | 4.3 | 0.3% | Sep 16, 2026 | PatrowlManager through 1.8.4 contains an improper access control vulnerability in the user listing API endpoint where th... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now