2026 CVE Vulnerabilities
64,824 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-55636 | MEDIUM | 5.7 | — | Sep 15, 2026 | Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.6, charts/capsule/templates... |
| CVE-2026-55591 | MEDIUM | 5.8 | — | Sep 15, 2026 | Signal K Server is a server application that runs on a central hub in a boat. Prior to 2.28.0, makeRemoteRequest() in sr... |
| CVE-2026-54724 | MEDIUM | 6.1 | — | Sep 15, 2026 | Kiwi TCMS is an open source test management system. Prior to 16.1, the account confirmation endpoint accepted an unvalid... |
| CVE-2026-50024 | MEDIUM | 5.3 | 0.4% | Sep 15, 2026 | GitHacker is a tool that restores Git repositories from exposed .git directories. In 1.1.7 and earlier, add_head_file_ta... |
| CVE-2026-47215 | MEDIUM | 4.8 | 0.2% | Sep 15, 2026 | SingularityCE and SingularityPRO are open source container platforms. Prior to SingularityCE 4.4.2 and SingularityPRO 4.... |
| CVE-2026-44282 | MEDIUM | 4.8 | — | Sep 15, 2026 | Decidim is a participatory democracy framework. Prior to 0.32.0, a low-privilege process-scoped administrator or electio... |
| CVE-2026-44163 | MEDIUM | 5.3 | 0.3% | Sep 15, 2026 | fluent-plugin-opentelemetry is a Fluentd input and output plugin for forwarding OpenTelemetry Protocol data. Prior to 0.... |
| CVE-2026-92082 | MEDIUM | 6.3 | 0.2% | Sep 15, 2026 | By default, Payara Server does not limit the number of failed login attempts, which can leave it vulnerable to brute for... |
| CVE-2026-91842 | MEDIUM | 4.1 | 0.4% | Sep 15, 2026 | A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert o... |
| CVE-2026-90439 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_v3_module module. When using HTTP/3 with OpenSSL v... |
| CVE-2026-88618 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | 1024-lab SmartAdmin v3.30.0 contains a stored cross-site scripting vulnerability in its file upload functionality. This ... |
| CVE-2026-55650 | MEDIUM | 4.4 | — | Sep 15, 2026 | Outerbase Studio is a lightweight browser-based database GUI supporting PostgreSQL, MySQL, and SQLite. In version 0.10.2... |
| CVE-2026-55617 | MEDIUM | 6.9 | — | Sep 15, 2026 | Hydro is a next-generation high-performance online judge platform. From 4.10.4 until 5.0.2, the session recreation logic... |
| CVE-2026-54637 | MEDIUM | 5.5 | 0.5% | Sep 15, 2026 | Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4-rc.3, the schedule... |
| CVE-2026-54254 | MEDIUM | 5.9 | 0.3% | Sep 15, 2026 | Cyberdrop-DL is a bulk asynchronous downloader for multiple file hosts. From 8.5.0 until 9.14.0, the Pixeldrain crawler ... |
| CVE-2026-54168 | MEDIUM | 6.5 | 0.4% | Sep 15, 2026 | Pipelines-as-Code is a CI/CD system that lets users define Tekton pipelines in source code repositories. Prior to 0.37.8... |
| CVE-2026-52724 | MEDIUM | 5.8 | — | Sep 15, 2026 | Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2... |
| CVE-2026-50166 | MEDIUM | 5.5 | 0.2% | Sep 15, 2026 | Kuma is a modern Envoy-based service mesh that can run on every cloud across both Kubernetes and VMs. Prior to 2.7.26, 2... |
| CVE-2026-49446 | MEDIUM | 6.1 | — | Sep 15, 2026 | Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as ... |
| CVE-2026-48987 | MEDIUM | 6.5 | — | Sep 15, 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, EventManager in src/pyload... |
| CVE-2026-48737 | MEDIUM | 4.9 | 0.2% | Sep 15, 2026 | pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev101, is_global_address in src/p... |
| CVE-2026-48722 | MEDIUM | 5.5 | 0.1% | Sep 15, 2026 | Nextflow is a DSL for data-driven computational pipelines. From 25.09.2-edge until 25.10.6 and 26.04.3, nextflow auth lo... |
| CVE-2026-47780 | MEDIUM | 6.9 | — | Sep 15, 2026 | free5GC is an open-source implementation of the 5G core network. In 4.2.3 and earlier, HandleCreateEeSubscriptions and H... |
| CVE-2026-25826 | MEDIUM | 4.9 | 0.1% | Sep 15, 2026 | An issue was discovered in Keyfactor SignServer before 7.6.0. The attribute ATTRIBUTESFILE in PKCS11CryptoToken can be s... |
| CVE-2026-92078 | MEDIUM | 6.5 | 0.1% | Sep 15, 2026 | Denial-of-service in the Security component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now