2026 CVE Vulnerabilities
64,803 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-48785 | MEDIUM | 4.8 | 0.1% | Sep 15, 2026 | Apptainer is an open source container platform. Prior to version 1.5.1, Image.AuthorizedPath applies plain string-prefix... |
| CVE-2026-39040 | MEDIUM | 5.4 | 0.2% | Sep 15, 2026 | BharatMLStack up to and including 1.3.0 is vulnerable to Cross Site Scripting (XSS) via the component Trufflebox UI (tru... |
| CVE-2026-39039 | MEDIUM | 5.3 | 0.2% | Sep 15, 2026 | In BharatMLStack up to and including v1.3.0, Trufflebox UI stores the JWT authentication token, full user object, and se... |
| CVE-2026-39038 | MEDIUM | 6.1 | 0.2% | Sep 15, 2026 | BharatMLStack up to and including v1.3.0 is vulnerable to Cross Site Scripting (XSS) in the component Trufflebox UI (tru... |
| CVE-2026-12910 | MEDIUM | 5.4 | 0.3% | Sep 15, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.1.8, 19.2 before 19.2.6, and 1... |
| CVE-2026-12751 | MEDIUM | 5.4 | 0.3% | Sep 15, 2026 | IBM Cloud Pak for Business Automation is vulnerable to HTML injection. A remote attacker could inject malicious HTML cod... |
| CVE-2026-12750 | MEDIUM | 5.4 | 0.3% | Sep 15, 2026 | IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authent... |
| CVE-2026-12749 | MEDIUM | 5.4 | 0.3% | Sep 15, 2026 | IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authent... |
| CVE-2026-12742 | MEDIUM | 5.4 | 0.2% | Sep 15, 2026 | IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted ... |
| CVE-2026-11927 | MEDIUM | 6.5 | 0.2% | Sep 15, 2026 | IBM Security Verify Identity Access reverse proxy may allow parameters to be injected in requests to third party service... |
| CVE-2026-11918 | MEDIUM | 5.4 | 0.3% | Sep 15, 2026 | IBM ContextForge MCP Gateway <= v1.0.4 IBM mcp-context-forge could allow an authenticated user to bypass protection mech... |
| CVE-2026-11864 | MEDIUM | 6.5 | 0.4% | Sep 15, 2026 | IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0... |
| CVE-2026-91855 | MEDIUM | 5.3 | — | Sep 15, 2026 | A security flaw has been discovered in Open5GS up to 2.7.7. Affected by this vulnerability is an unknown functionality o... |
| CVE-2026-91854 | MEDIUM | 4.3 | 0.3% | Sep 15, 2026 | A vulnerability was identified in code-projects Record Management System 1.0. Affected is an unknown function of the fil... |
| CVE-2026-81897 | MEDIUM | 5.4 | 0.1% | Sep 15, 2026 | In Concrete CMS below CMS 9.5.3, the save_control action in the Express entities forms dashboard controller did not vali... |
| CVE-2026-81896 | MEDIUM | 5.4 | 0.1% | Sep 15, 2026 | Concrete CMS before 9.5.3 does not apply HTML entity encoding to user-defined Form block question labels when rendering ... |
| CVE-2026-81894 | MEDIUM | 5.4 | 0.1% | Sep 15, 2026 | Concrete CMS 9.5.2 and below is vulnerable to stored DOM-based Cross-site Scripting (XSS) via the Gallery block's per-im... |
| CVE-2026-79705 | MEDIUM | 4.5 | 0.2% | Sep 15, 2026 | A flaw was found in the buildah/copier Go package. When used outside of Buildah by a non-root caller, a crafted tar arch... |
| CVE-2026-79699 | MEDIUM | 4.4 | 0.1% | Sep 15, 2026 | A flaw was found in the containers/storage library. A crafted tar archive containing a malicious whiteout header (e.g. v... |
| CVE-2026-55863 | MEDIUM | 5.3 | 0.3% | Sep 15, 2026 | motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program w... |
| CVE-2026-54561 | MEDIUM | 6.2 | — | Sep 15, 2026 | MCP Memory Keeper is an MCP server for persistent context management in AI coding assistants. Prior to 0.13.0, context_i... |
| CVE-2026-54503 | MEDIUM | 4.3 | — | Sep 15, 2026 | plone.app.textfield provides a zope.schema-style field type called RichText for storing a value with a related MIME type... |
| CVE-2026-53658 | MEDIUM | 6.3 | 0.3% | Sep 15, 2026 | Fabric CA is a Certificate Authority for Hyperledger Fabric. Prior to 1.5.21, when fabric-ca is configured with an LDAP ... |
| CVE-2026-91992 | MEDIUM | 5.9 | 0.2% | Sep 15, 2026 | Tornado before 6.5.7 contains a credential leak vulnerability in CurlAsyncHTTPClient where pycurl handles are reused acr... |
| CVE-2026-91991 | MEDIUM | 5.4 | 0.2% | Sep 15, 2026 | Tornado before 6.5.8 contains an incomplete fix for cookie attribute injection that allows attackers to inject arbitrary... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now