2026 CVE Vulnerabilities
64,848 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-90793 | MEDIUM | 5.4 | 0.3% | Sep 14, 2026 | A vulnerability has been found in GPAC up to f1219cde. Impacted is the function gf_node_get_name of the file scenegraph/... |
| CVE-2026-90792 | MEDIUM | 4.3 | — | Sep 14, 2026 | A flaw has been found in GPAC up to f1219cde. This issue affects the function gf_node_list_get_child of the file scenegr... |
| CVE-2026-90463 | MEDIUM | 4 | 0.1% | Sep 14, 2026 | A flaw was found in the sssd NSS responder. This input validation vulnerability allows a local attacker, by sending spec... |
| CVE-2026-88819 | MEDIUM | 6.3 | 0.1% | Sep 14, 2026 | In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID. |
| CVE-2026-55795 | MEDIUM | 6.9 | — | Sep 14, 2026 | Craft Commerce is an ecommerce platform for Craft CMS. From 4.0.0 until 4.11.2 and 5.6.5, CartController in src/controll... |
| CVE-2026-55236 | MEDIUM | 5.9 | — | Sep 14, 2026 | langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, the langgraph-api run-cre... |
| CVE-2026-55235 | MEDIUM | 5.9 | 0.2% | Sep 14, 2026 | langgraph-api implements the LangGraph API for rapid development and testing. Prior to 0.10.0, langgraph-api permits a r... |
| CVE-2026-54529 | MEDIUM | 5.3 | — | Sep 14, 2026 | SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to 0.27.1, ModelView.sort_query in sqladmin/models.p... |
| CVE-2026-53708 | MEDIUM | 6.6 | — | Sep 14, 2026 | ContextForge is an AI gateway, registry, and proxy that provides centralized discovery, guardrails, and management for M... |
| CVE-2026-4103 | MEDIUM | 6.4 | 0.2% | Sep 14, 2026 | Insufficient HTML sanitization in the Publisher Portal and Developer Portal allows untrusted user input to be rendered w... |
| CVE-2026-90791 | MEDIUM | 6.3 | 0.3% | Sep 14, 2026 | A vulnerability was detected in GPAC up to f1219cde. This vulnerability affects the function gf_node_unregister of the f... |
| CVE-2026-90790 | MEDIUM | 6.3 | — | Sep 14, 2026 | A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3. This affects the function _dispatch_not... |
| CVE-2026-82437 | MEDIUM | 4.3 | — | Sep 14, 2026 | Description The Logviewer offers `logs.users` and `logs.groups` so operators can control who may read log content. For ... |
| CVE-2026-82434 | MEDIUM | 6.5 | — | Sep 14, 2026 | Description When ZooKeeper authentication is configured, Storm deliberately retains `storm.zookeeper.topology.auth.payl... |
| CVE-2026-82433 | MEDIUM | 6.5 | — | Sep 14, 2026 | Description `getNimbusConf` returned the complete daemon configuration without redaction after only a user-level author... |
| CVE-2026-82426 | MEDIUM | 6.5 | — | Sep 14, 2026 | Description Nimbus accepted the `uploadedJarLocation` argument of `submitTopology` / `submitTopologyWithOpts` as a serv... |
| CVE-2026-82019 | MEDIUM | 4.2 | 0.3% | Sep 14, 2026 | TripleLift's ad rendering script (video-bundle.js) contains a DOM-based cross-site scripting vulnerability that allows u... |
| CVE-2026-57128 | MEDIUM | 4.3 | 0.2% | Sep 14, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, the SSE server in src/praisonai-agents/praison... |
| CVE-2026-57120 | MEDIUM | 6.5 | 0.3% | Sep 14, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, execute_code sandbox mode permits runtime asse... |
| CVE-2026-57115 | MEDIUM | 6.5 | 0.3% | Sep 14, 2026 | PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.59, SpiderTools.scrape_page validates only the ini... |
| CVE-2026-12985 | MEDIUM | 6.8 | 0.3% | Sep 14, 2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 Mattermost failed to validate Dynamic Client Re... |
| CVE-2026-90941 | MEDIUM | 4.3 | 0.2% | Sep 14, 2026 | novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that all... |
| CVE-2026-90940 | MEDIUM | 5.3 | 0.3% | Sep 14, 2026 | novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endp... |
| CVE-2026-90939 | MEDIUM | 6.5 | 0.3% | Sep 14, 2026 | novel-plus through 5.3.3 contains an information disclosure vulnerability in the /sys/user/list endpoint that lacks prop... |
| CVE-2026-90788 | MEDIUM | 4.7 | 1.6% | Sep 14, 2026 | A security flaw has been discovered in magicblack MacCMS10 2026.1000.4055. Affected by this vulnerability is an unknown ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now