2026 CVE Vulnerabilities
64,840 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-90810 | MEDIUM | 6.3 | 0.2% | Sep 14, 2026 | A security flaw has been discovered in cosmicstack-labs mercury-agent up to 1.1.13. The impacted element is the function... |
| CVE-2026-90808 | MEDIUM | 6.3 | — | Sep 14, 2026 | A vulnerability was determined in HKUDS nanobot up to 0.2.1. Impacted is the function ExecTool._guard_command/ExecTool._... |
| CVE-2026-89021 | MEDIUM | 6.9 | 0.4% | Sep 14, 2026 | MikroTik RouterOS before 7.24.2 contains a path traversal vulnerability in the container package OCI/tar image extractio... |
| CVE-2026-89020 | MEDIUM | 4.3 | 0.5% | Sep 14, 2026 | MikroTik RouterOS before 7.23.4 (long-term) and 7.24.2 (stable) contains a stack-based buffer overflow vulnerability in ... |
| CVE-2026-82519 | MEDIUM | 4.3 | 0.2% | Sep 14, 2026 | Really Simple Security plugin for WordPress before 9.8.2 contains a missing authorization check vulnerability that allow... |
| CVE-2026-19543 | MEDIUM | 6.2 | 0.2% | Sep 14, 2026 | IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART 9.0.0.1, and ART 9.0.0.2 performs input valid... |
| CVE-2026-18515 | MEDIUM | 4.3 | 0.3% | Sep 14, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to place files into the file system with Naviga... |
| CVE-2026-18151 | MEDIUM | 4.2 | 0.1% | Sep 14, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race c... |
| CVE-2026-15893 | MEDIUM | 6.5 | — | Sep 14, 2026 | net_if_ipv6_calc_reachable_time() in subsys/net/ip/net_if.c derives a randomized ND reachable time from ipv6->base_reach... |
| CVE-2026-91081 | MEDIUM | 5.8 | 0.2% | Sep 14, 2026 | Docs through 5.6.1 contains a server-side request forgery vulnerability in the cors-proxy endpoint that allows anonymous... |
| CVE-2026-91021 | MEDIUM | 5.4 | 0.1% | Sep 14, 2026 | Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share ren... |
| CVE-2026-90807 | MEDIUM | 6.3 | 0.3% | Sep 14, 2026 | A vulnerability was found in nanocoai NanoClaw up to 2.1.17. This issue affects the function forwardAttachedFiles of the... |
| CVE-2026-90806 | MEDIUM | 6.3 | — | Sep 14, 2026 | A vulnerability has been found in DjangoCRM django-crm up to 1.2. This vulnerability affects the function BulkUpdateCase... |
| CVE-2026-57581 | MEDIUM | 5.3 | 0.4% | Sep 14, 2026 | DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, applic... |
| CVE-2026-57570 | MEDIUM | 6.5 | — | Sep 14, 2026 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha... |
| CVE-2026-55847 | MEDIUM | 6.1 | — | Sep 14, 2026 | Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the ansi.js ... |
| CVE-2026-55846 | MEDIUM | 6.2 | 0.1% | Sep 14, 2026 | Allure 2 is the version 2.x branch of Allure Report, a multi-language test reporting tool. Prior to 2.39.0, the HTTP ser... |
| CVE-2026-55832 | MEDIUM | 6.1 | — | Sep 14, 2026 | Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.17, 0.22.3, and 0.23.2... |
| CVE-2026-54723 | MEDIUM | 6.5 | — | Sep 14, 2026 | devpi is a Python package index staging server and packaging, testing, and release tool. Prior to 6.20.2 and 7.0.0b3, a ... |
| CVE-2026-54181 | MEDIUM | 5.4 | — | Sep 14, 2026 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha... |
| CVE-2026-54177 | MEDIUM | 6.6 | 0.7% | Sep 14, 2026 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha... |
| CVE-2026-54176 | MEDIUM | 6.5 | — | Sep 14, 2026 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha... |
| CVE-2026-54150 | MEDIUM | 6.9 | — | Sep 14, 2026 | next-video is a library for adding video to Next.js applications. Prior to 2.8.1, the GET endpoint exported by next-vide... |
| CVE-2026-53495 | MEDIUM | 6.8 | 0.2% | Sep 14, 2026 | containerd is an open-source container runtime. Prior to 1.7.35, 2.0.12, 2.2.8, and 2.3.5, containerd on Linux with the ... |
| CVE-2026-50157 | MEDIUM | 6.5 | — | Sep 14, 2026 | Auth0 Symfony is a Symfony SDK for Auth0 Authentication and Management APIs. From 5.0.0-BETA0 until 5.9.0, the Authorize... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now