2026 CVE Vulnerabilities
64,803 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-91987 | MEDIUM | 6.5 | 0.5% | Sep 15, 2026 | atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in the _estimate_batch_cost function that returns zero... |
| CVE-2026-91986 | MEDIUM | 5.4 | 0.2% | Sep 15, 2026 | gitoxide gix-transport before 0.59.2 fails to filter control characters in git-daemon connect requests, allowing attacke... |
| CVE-2026-91984 | MEDIUM | 4.3 | 0.2% | Sep 15, 2026 | Vikunja before 2.6.0 fails to validate that user-supplied project_view_id in task-position requests belongs to the task'... |
| CVE-2026-91983 | MEDIUM | 4.3 | 0.3% | Sep 15, 2026 | Vikunja before 2.6.0 contains an API token scope bypass vulnerability in task read endpoints where authorization fails t... |
| CVE-2026-91982 | MEDIUM | 4.3 | 0.3% | Sep 15, 2026 | Vikunja before 2.6.0 continues to expose the raw TOTP shared secret after enrollment through the GET /api/v1/user/settin... |
| CVE-2026-91981 | MEDIUM | 4.3 | 0.2% | Sep 15, 2026 | Vikunja versions before 2.6.0 fail to properly validate link-share tokens in the v2 API user search endpoints. Attackers... |
| CVE-2026-91980 | MEDIUM | 4.3 | 0.3% | Sep 15, 2026 | vikunja before 2.6.0 fails to validate team access when attaching teams to projects, allowing authenticated users to enu... |
| CVE-2026-91979 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | Vikunja before 2.6.0 fails to limit archive expansion during data import, allowing authenticated users to cause denial o... |
| CVE-2026-91971 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | Vikunja before 2.6.0 fails to apply pixel decode limits to avatar and project-background upload endpoints, allowing auth... |
| CVE-2026-91970 | MEDIUM | 6.5 | 0.4% | Sep 15, 2026 | Vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the Planka migrator that fails to enforce a... |
| CVE-2026-91969 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the POST /api/v2/migration/csv/migrate endp... |
| CVE-2026-91968 | MEDIUM | 6.5 | 0.4% | Sep 15, 2026 | vikunja versions before 2.6.0 contain a resource exhaustion vulnerability in the task-filter endpoint that accepts deepl... |
| CVE-2026-91967 | MEDIUM | 5 | 0.3% | Sep 15, 2026 | AVideo through 29.0 contains a blind server-side request forgery vulnerability in the getHeaderContentTypeFromURL functi... |
| CVE-2026-91966 | MEDIUM | 5.8 | 0.4% | Sep 15, 2026 | AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability... |
| CVE-2026-91963 | MEDIUM | 6.5 | 0.6% | Sep 15, 2026 | FreeRDP versions before 3.31.0 contain an uninitialized heap memory disclosure vulnerability in the urbdrc USB redirecti... |
| CVE-2026-91962 | MEDIUM | 6.3 | 0.2% | Sep 15, 2026 | FreeRDP before 3.31.0 contains an integer overflow in the audin Apple backends when processing FramesPerPacket values fr... |
| CVE-2026-91961 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails ... |
| CVE-2026-91960 | MEDIUM | 6.5 | 0.4% | Sep 15, 2026 | FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allow... |
| CVE-2026-91959 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway t... |
| CVE-2026-91958 | MEDIUM | 6.6 | 0.2% | Sep 15, 2026 | FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbo... |
| CVE-2026-91956 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function tha... |
| CVE-2026-91954 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits... |
| CVE-2026-91953 | MEDIUM | 6.5 | 0.4% | Sep 15, 2026 | FreeRDP versions before 3.31.0 contain a heap buffer overflow vulnerability in nego_send_negotiation_request() that fail... |
| CVE-2026-91952 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding... |
| CVE-2026-91951 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_curr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now