2026 CVE Vulnerabilities
64,788 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-92782 | HIGH | 8.1 | 0.4% | Sep 16, 2026 | Chroma through 1.5.9 fails to validate tenant and database segments when resolving collections, allowing authenticated a... |
| CVE-2026-92780 | HIGH | 8.8 | 0.5% | Sep 16, 2026 | KnowStreaming through 3.4.1 fails to enforce role-based access control on REST API endpoints, allowing any authenticated... |
| CVE-2026-92779 | HIGH | 7.6 | 0.5% | Sep 16, 2026 | Builder.io Gen2 SDKs through versions 5.2.11 and 0.25.13 contain a prototype pollution vulnerability in the deep-set hel... |
| CVE-2026-92776 | HIGH | 8.1 | 0.4% | Sep 16, 2026 | Wiki.js through 2.5.314 fails to require path separators when matching START and END page rules, allowing attackers to a... |
| CVE-2026-92773 | HIGH | 7.1 | 0.3% | Sep 16, 2026 | Trigger.dev before 4.6.0 fails to verify that an authenticated user controls a GitHub App installation before binding it... |
| CVE-2026-92772 | HIGH | 7.1 | — | Sep 16, 2026 | Leantime before 3.9.6 contains an authorization bypass vulnerability in the HTMX plugin install endpoint that lacks perm... |
| CVE-2026-92763 | HIGH | 8.1 | 0.5% | Sep 16, 2026 | Rundeck through 6.2.1 fails to properly authorize the importConfig and importNodesSources parameters in the project arch... |
| CVE-2026-92762 | HIGH | 8.8 | 0.7% | Sep 16, 2026 | Pelican Panel versions before 1.0.0-beta35 enforce startup write permissions only through disabled form controls rather ... |
| CVE-2026-92761 | HIGH | 8.8 | 0.4% | Sep 16, 2026 | WebVirtCloud fails to properly validate permission flags in UserInstance grants, allowing view-only users to perform pri... |
| CVE-2026-92753 | HIGH | 7.1 | 0.3% | Sep 16, 2026 | PatrowlManager through 1.8.4 contains an authorization bypass vulnerability in the events and alerts API endpoints that ... |
| CVE-2026-92752 | HIGH | 8.3 | 0.3% | Sep 16, 2026 | metasfresh DocumentAttachmentsRestController and CommentsRestController endpoints check only that callers are logged in ... |
| CVE-2026-92751 | HIGH | 8.1 | 0.2% | Sep 16, 2026 | CMAK through 3.0.0.6 fails to install a cross-site request forgery filter, allowing attackers to perform state-changing ... |
| CVE-2026-92749 | HIGH | 8.1 | 0.5% | Sep 16, 2026 | SafeLine through 9.4.1 derives the management console session-signing secret from a time-seeded math/rand generator, all... |
| CVE-2026-92748 | HIGH | 8.8 | 0.8% | Sep 16, 2026 | BC Security Empire before 6.7.1 fails to validate the multipart filename parameter in upload endpoints, allowing authent... |
| CVE-2026-76425 | HIGH | 7.6 | — | Sep 16, 2026 | A vulnerability in the APIs of Cisco ISE could allow an authenticated, remote attacker to conduct SQL injection attacks ... |
| CVE-2026-76424 | HIGH | 7.2 | — | Sep 16, 2026 | A vulnerability in the REST API of Cisco ISE could allow an authenticated, remote attacker to upload or copy arbitrary f... |
| CVE-2026-76413 | HIGH | 8.2 | — | Sep 16, 2026 | A vulnerability in Cisco Adaptive Security Device Manager (ASDM) single sign-on (SSO) handler for Cisco Secure FMC Softw... |
| CVE-2026-76412 | HIGH | 8.5 | — | Sep 16, 2026 | A vulnerability in the remote diagnostics debugger of Cisco Secure FMC Software could allow an authenticated, remote att... |
| CVE-2026-76409 | HIGH | 8.8 | — | Sep 16, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering t... |
| CVE-2026-63506 | HIGH | 8.8 | — | Sep 16, 2026 | Tina is a headless content management system. Prior to @tinacms/auth 1.1.4 and next-tinacms-azure 15.0.1, isAuthorized a... |
| CVE-2026-62997 | HIGH | 7.7 | — | Sep 16, 2026 | Kedro-Datasets provides data connectors for Kedro. From version 5.0.0 until 9.5.0, kedro_datasets_experimental.pytorch.P... |
| CVE-2026-20360 | HIGH | 8.8 | — | Sep 16, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering t... |
| CVE-2026-20352 | HIGH | 8.6 | — | Sep 16, 2026 | A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote att... |
| CVE-2026-20344 | HIGH | 8.8 | — | Sep 16, 2026 | A vulnerability in the web-based management interface of Cisco Secure FMC Software could allow an authenticated, remote ... |
| CVE-2026-20343 | HIGH | 7.5 | — | Sep 16, 2026 | A vulnerability in a critical API for Cisco Secure FMC Software could allow an unauthenticated, remote attacker to downl... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now