2026 CVE Vulnerabilities
64,788 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-92593 | HIGH | 8.8 | 0.4% | Sep 16, 2026 | Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirec... |
| CVE-2026-92592 | HIGH | 8.8 | 0.5% | Sep 16, 2026 | Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun c... |
| CVE-2026-92582 | HIGH | 7.1 | 0.1% | Sep 16, 2026 | AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.js... |
| CVE-2026-92580 | HIGH | 8.8 | 1.1% | Sep 16, 2026 | In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClie... |
| CVE-2026-92578 | HIGH | 8.1 | 0.3% | Sep 16, 2026 | WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a... |
| CVE-2026-92577 | HIGH | 7.5 | 0.3% | Sep 16, 2026 | In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title... |
| CVE-2026-92576 | HIGH | 8.6 | — | Sep 16, 2026 | HKUDS nanobot before 0.3.0 contains a server-side request forgery vulnerability in the WebFetchTool component where the ... |
| CVE-2026-85469 | HIGH | 8 | — | Sep 16, 2026 | A flaw was found in quay-builder-qemu. A remote attacker could exploit this by compromising the upstream `Noelware/docke... |
| CVE-2026-61592 | HIGH | 7.4 | — | Sep 16, 2026 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to ... |
| CVE-2026-61591 | HIGH | 8.1 | — | Sep 16, 2026 | djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to ... |
| CVE-2026-92816 | HIGH | 7.8 | 0.2% | Sep 16, 2026 | ComfyUI before 0.30.0 fails to sanitize folder_name input in dataset save nodes, allowing attackers to write files to ar... |
| CVE-2026-92815 | HIGH | 7.5 | 0.4% | Sep 16, 2026 | changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attac... |
| CVE-2026-92806 | HIGH | 8.1 | 0.2% | Sep 16, 2026 | phpList versions before 3.6.17 fail to validate cross-site request forgery tokens in the mass subscriber removal form ha... |
| CVE-2026-92804 | HIGH | 7.1 | 0.3% | Sep 16, 2026 | Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token ... |
| CVE-2026-92801 | HIGH | 8.8 | 0.3% | Sep 16, 2026 | cc-connect through 1.5.0 fails to enforce per-user allowlist filtering in the onCardAction handler for Feishu interactiv... |
| CVE-2026-92796 | HIGH | 8.8 | 0.3% | Sep 16, 2026 | Manticore Search versions 27.0.0 before 28.4.4 fail to validate permissions for all statements in multi-statement SQL re... |
| CVE-2026-92794 | HIGH | 7.5 | 0.3% | Sep 16, 2026 | OpenSign through 2.41.3 fails to validate caller identity in the getDocument cloud function when one-time-password verif... |
| CVE-2026-92793 | HIGH | 8.1 | 0.3% | Sep 16, 2026 | GoAdmin through 1.2.26 fails to properly anchor the logout pattern when checking permissions, allowing authenticated use... |
| CVE-2026-92792 | HIGH | 7.5 | 0.5% | Sep 16, 2026 | OpenNHP through 1.0.2 selects its trusted-execution attestation verifier based on attacker-supplied evidence containing ... |
| CVE-2026-92791 | HIGH | 7.5 | 0.6% | Sep 16, 2026 | Uber Kraken through 0.1.29 fails to validate the tag parameter in the /tags/{tag} endpoint, allowing unauthenticated att... |
| CVE-2026-92788 | HIGH | 8.8 | 0.5% | Sep 16, 2026 | Coze Studio through 0.5.1 fails to validate that table names in workflow SQL customization nodes belong to the caller's ... |
| CVE-2026-92786 | HIGH | 7.8 | 0.2% | Sep 16, 2026 | LightGBM through 4.7.0 fails to validate child and split array values when parsing text models, allowing attackers to wr... |
| CVE-2026-92785 | HIGH | 8.1 | 0.6% | Sep 16, 2026 | Angel through 3.3.0 deserializes untrusted setAlgoMetrics payload using Kryo without class registration or allowlist val... |
| CVE-2026-92784 | HIGH | 7.5 | 0.5% | Sep 16, 2026 | @refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source co... |
| CVE-2026-92783 | HIGH | 8.1 | 0.4% | Sep 16, 2026 | Yeti through 2.11.0 fails to validate caller permissions in the DELETE /api/v2/rbac/{id} endpoint, allowing users with r... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now