2026 CVE Vulnerabilities
64,824 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-91961 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | FreeRDP before 3.31.0 contains a denial-of-service vulnerability in the URBDRC control-transfer request path that fails ... |
| CVE-2026-91960 | MEDIUM | 6.5 | 0.4% | Sep 15, 2026 | FreeRDP versions before 3.31.0 contain an integer overflow in WinPR's Stream_EnsureRemainingCapacity function that allow... |
| CVE-2026-91959 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | FreeRDP before 3.31.0 contains a buffer over-read vulnerability in the rts_read_result function within the RPC gateway t... |
| CVE-2026-91958 | MEDIUM | 6.6 | 0.2% | Sep 15, 2026 | FreeRDP versions before 3.31.0 fail to validate MonitorIds array values when parsing RDP connection files, allowing unbo... |
| CVE-2026-91956 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the URBDRC channel's func_get_ep_desc function tha... |
| CVE-2026-91954 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | FreeRDP before 3.31.0 contains a null pointer dereference vulnerability in gdi_surface_bits when processing Surface Bits... |
| CVE-2026-91953 | MEDIUM | 6.5 | 0.4% | Sep 15, 2026 | FreeRDP versions before 3.31.0 contain a heap buffer overflow vulnerability in nego_send_negotiation_request() that fail... |
| CVE-2026-91952 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding... |
| CVE-2026-91951 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | FreeRDP versions before 3.31.0 contain an out-of-bounds write vulnerability in the urbdrc client channel's urb_send_curr... |
| CVE-2026-91950 | MEDIUM | 6.5 | 0.5% | Sep 15, 2026 | FreeRDP before 3.31.0 contains an out-of-bounds read vulnerability in the rdpdr_dump_packet function due to 32-bit unsig... |
| CVE-2026-91946 | MEDIUM | 6.5 | 0.4% | Sep 15, 2026 | FreeRDP versions before 3.31.0 contain an information disclosure vulnerability in the RDPGFX server's ResetGraphics PDU ... |
| CVE-2026-91945 | MEDIUM | 6.5 | 0.6% | Sep 15, 2026 | FreeRDP versions before 3.31.0 contain an out-of-bounds read vulnerability in smartcard response decoders that fail to v... |
| CVE-2026-91944 | MEDIUM | 6.1 | 0.2% | Sep 15, 2026 | crawl4ai versions before 0.9.3 contain a DOM-based cross-site scripting vulnerability in the Playground UI where the for... |
| CVE-2026-91942 | MEDIUM | 5.4 | 0.2% | Sep 15, 2026 | crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns u... |
| CVE-2026-91936 | MEDIUM | 6.8 | 0.3% | Sep 15, 2026 | Flowise versions before 3.1.4 contain a script injection vulnerability in Docker image build workflows where workflow_di... |
| CVE-2026-91849 | MEDIUM | 6.3 | 0.3% | Sep 15, 2026 | A security flaw has been discovered in WuzhiCMS up to 4.1.0. This affects the function member::setAvatar of the file /in... |
| CVE-2026-89307 | MEDIUM | 5.1 | 0.3% | Sep 15, 2026 | The "Firma Circolare" feature in the "Design Scuole Italia" WordPress theme allows an authenticated attacker to inject a... |
| CVE-2026-88620 | MEDIUM | 4.3 | 0.2% | Sep 15, 2026 | SmartAdmin API Java17 SpringBoot3 version 3.30.0 contains an improper authorization vulnerability in the /employee/query... |
| CVE-2026-87793 | MEDIUM | 5.1 | 0.4% | Sep 15, 2026 | The "Design Scuole Italia" WordPress theme is affected by a Reflected XSS vulnerability in the filters-scheda-didattica.... |
| CVE-2026-59157 | MEDIUM | 6.5 | 0.5% | Sep 15, 2026 | webhookd is a minimalist webhook server that triggers shell scripts and external processes through HTTP requests. Prior ... |
| CVE-2026-58196 | MEDIUM | 4.7 | — | Sep 15, 2026 | ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior ... |
| CVE-2026-55828 | MEDIUM | 6 | — | Sep 15, 2026 | qbee transport is a remote access transport protocol implementation. Prior to 1.26.25, the extractTar routine uses stric... |
| CVE-2026-55776 | MEDIUM | 6.5 | 0.5% | Sep 15, 2026 | OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an authenticated OpenBao caller with... |
| CVE-2026-55770 | MEDIUM | 6.8 | 0.4% | Sep 15, 2026 | OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao used EscapeLDAPValue, an RFC... |
| CVE-2026-55701 | MEDIUM | 6.9 | 0.7% | Sep 15, 2026 | The OpenTelemetry Collector Contrib repository contains components for the OpenTelemetry Collector. Prior to 0.151.0, th... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now