2026 CVE Vulnerabilities
64,824 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-52822 | MEDIUM | 5.3 | 0.4% | Sep 15, 2026 | Kimai is an open-source time tracking application. Prior to 2.58.0, PATCH /api/timesheets/{id}/restart, PATCH /api/times... |
| CVE-2026-52821 | MEDIUM | 5.3 | 0.3% | Sep 15, 2026 | Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/activity/create/{p... |
| CVE-2026-52820 | MEDIUM | 5.3 | 0.3% | Sep 15, 2026 | Kimai is an open-source time tracking application. Prior to 2.57.0, PATCH /api/timesheets/{id} and POST /api/timesheets ... |
| CVE-2026-52819 | MEDIUM | 6.3 | 0.4% | Sep 15, 2026 | Kimai is an open-source time tracking application. Prior to 2.57.0, the GET /api/timesheets list endpoint accepts user a... |
| CVE-2026-1759 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | Improper handling of insufficient permissions or privileges vulnerability in Secomea GateManager allows Privilege Escala... |
| CVE-2026-91859 | MEDIUM | 5.3 | 0.5% | Sep 15, 2026 | Affected versions of MISP can record incorrect access-log data for requests that terminate in an exception. Because Ca... |
| CVE-2026-91857 | MEDIUM | 5.3 | 0.2% | Sep 15, 2026 | Affected versions of MISP expose several state-changing controller actions without restricting them to POST. The affec... |
| CVE-2026-62280 | MEDIUM | 6.1 | 0.2% | Sep 15, 2026 | Open Access Management (OpenAM) is an access management solution. From 13.0.0 until 16.1.2, the OAuth2 authorize endpoin... |
| CVE-2026-59341 | MEDIUM | 4.2 | 0.3% | Sep 15, 2026 | A security vulnerability exists in the Sealed Secrets controller's unauthenticated POST endpoints. By submitting a modif... |
| CVE-2026-44202 | MEDIUM | 5.3 | 0.4% | Sep 15, 2026 | Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the /sessionservice addSessionListene... |
| CVE-2026-91851 | MEDIUM | 5.3 | 0.3% | Sep 15, 2026 | Affected versions of MISP incorrectly filter dashboard templates that are restricted to a specific permission flag. Da... |
| CVE-2026-91826 | MEDIUM | 4.4 | 0.1% | Sep 15, 2026 | Stack-based buffer overflow vulnerability in Samsung Opensource rLottie allows attackers to overflow buffers, leading to... |
| CVE-2026-91819 | MEDIUM | 6.9 | 0.2% | Sep 15, 2026 | Affected versions of MISP rely on CakePHP request-method override processing in a way that can disable CSRF and form-sec... |
| CVE-2026-91091 | MEDIUM | 4.3 | 0.4% | Sep 15, 2026 | A vulnerability was identified in GPAC up to f1219cde. The impacted element is the function gf_node_list_insert_child of... |
| CVE-2026-91089 | MEDIUM | 6.3 | 0.3% | Sep 15, 2026 | A vulnerability was found in GPAC up to f1219cde. Impacted is the function gf_node_get_name_and_id of the file scenegrap... |
| CVE-2026-91088 | MEDIUM | 4.8 | 0.1% | Sep 15, 2026 | A vulnerability has been found in GPAC up to f1219cde. This issue affects the function gf_url_concatenate_ex of the file... |
| CVE-2026-91086 | MEDIUM | 6.3 | 0.3% | Sep 15, 2026 | A security vulnerability has been detected in GPAC up to f1219cde. Affected by this issue is the function mpgviddmx_proc... |
| CVE-2026-91005 | MEDIUM | 6.3 | 0.2% | Sep 15, 2026 | A vulnerability was found in SourceCodester Online Faculty Clearance System 1.0. This affects the function move_uploaded... |
| CVE-2026-89141 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Insecure Direct Obje... |
| CVE-2026-18063 | MEDIUM | 6.4 | 0.2% | Sep 15, 2026 | The Job Postings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'position_button' parameter i... |
| CVE-2026-15402 | MEDIUM | 6.4 | 0.3% | Sep 15, 2026 | The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to S... |
| CVE-2026-91002 | MEDIUM | 5.3 | 0.4% | Sep 15, 2026 | A weakness has been identified in stamparm maltrail up to 3.0.1. This vulnerability affects the function _blacklist of t... |
| CVE-2026-81320 | MEDIUM | 5.5 | 0.1% | Sep 15, 2026 | A flaw was found in hawtio-operator. When a custom Route TLS secret is configured and the operator runs at debug log lev... |
| CVE-2026-81303 | MEDIUM | 6.3 | 0.3% | Sep 15, 2026 | A flaw was found in hawtio-operator. The operator holds routes/custom-host:create permission cluster-wide and writes the... |
| CVE-2026-18232 | MEDIUM | 5.3 | 0.2% | Sep 15, 2026 | The WP Directory Kit WordPress plugin through 1.5.7 does not check the status or ownership of a listing before returning... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now