2026 CVE Vulnerabilities
64,848 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-90786 | MEDIUM | 5.3 | 0.4% | Sep 14, 2026 | A vulnerability was determined in Dvidelabs flatcc up to 0.6.3. This impacts the function align_order_members of the fil... |
| CVE-2026-90785 | MEDIUM | 5.3 | — | Sep 14, 2026 | A vulnerability was found in Dvidelabs flatcc up to 0.6.3. This affects the function analyze_struct of the file src/comp... |
| CVE-2026-86349 | MEDIUM | 4.3 | 0.2% | Sep 14, 2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.8, 10.11.x <= 10.11.22 fail to limit the nesting ... |
| CVE-2026-86348 | MEDIUM | 4.3 | 0.2% | Sep 14, 2026 | Mattermost versions <=11.9 11.0.9 11.4.8 11.7.7 10.22.11.0 fail to recover from handler panics, which allows an authenti... |
| CVE-2026-84179 | MEDIUM | 6.5 | — | Sep 14, 2026 | Description getTopologyPageInfo merged the Nimbus daemon configuration with the topology's own configuration and retu... |
| CVE-2026-82920 | MEDIUM | 5.5 | 0.2% | Sep 14, 2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7 fail to enforce authorization boundaries on the... |
| CVE-2026-7208 | MEDIUM | 5.3 | 0.3% | Sep 14, 2026 | Yealink SIP-T33G firmware versions 124.86.x.x prior to 124.87.0.0 contain a race condition vulnerability that allows aut... |
| CVE-2026-73191 | MEDIUM | 6.1 | — | Sep 14, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Syncope. When the Syncope SRA is config... |
| CVE-2026-90957 | MEDIUM | 5.1 | 0.2% | Sep 14, 2026 | Affected versions of MISP serve uploaded SVG images inline without a restrictive browser sandbox. The commit explains ... |
| CVE-2026-90955 | MEDIUM | 4.6 | 0.1% | Sep 14, 2026 | Affected versions of MISP’s interactive CLI shell do not reliably preserve the identity of the impersonated MISP user ac... |
| CVE-2026-90936 | MEDIUM | 4.3 | 0.2% | Sep 14, 2026 | Froxlor before 2.3.7 fails to properly scope sender alias lookups to the current customer in customer_email.php. Authent... |
| CVE-2026-90935 | MEDIUM | 4.3 | 0.2% | Sep 14, 2026 | Froxlor before 2.3.7 fails to validate the mysql_server parameter against a customer's allowed_mysqlserver allowlist in ... |
| CVE-2026-90934 | MEDIUM | 4.3 | 0.2% | Sep 14, 2026 | EspoCRM before 10.0.4 contains a field-level security bypass vulnerability in the meeting and call attendees endpoints t... |
| CVE-2026-90931 | MEDIUM | 5.4 | 0.2% | Sep 14, 2026 | LaraDashboard versions 0.9.0 through 1.2.2 fail to sanitize SVG file content during media upload, allowing authenticated... |
| CVE-2026-90930 | MEDIUM | 6.8 | 0.5% | Sep 14, 2026 | File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reappl... |
| CVE-2026-90928 | MEDIUM | 6.5 | 0.4% | Sep 14, 2026 | File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads e... |
| CVE-2026-90927 | MEDIUM | 6.5 | 0.4% | Sep 14, 2026 | filebrowser through 2.63.23 fails to limit WebSocket message size in the /api/command handler before checking permission... |
| CVE-2026-90784 | MEDIUM | 5.3 | — | Sep 14, 2026 | A vulnerability has been found in Dvidelabs flatcc up to 0.6.3. The impacted element is the function fb_clear_parser of ... |
| CVE-2026-90716 | MEDIUM | 5.5 | 0.3% | Sep 14, 2026 | A vulnerability was detected in marcobambini Gravity up to 0.9.7. This impacts the function parse_number_expression of t... |
| CVE-2026-90714 | MEDIUM | 6.3 | 0.3% | Sep 14, 2026 | A weakness has been identified in marcobambini Gravity up to 0.9.7. The impacted element is an unknown function of the f... |
| CVE-2026-78318 | MEDIUM | 6.1 | — | Sep 14, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Syncope. ... |
| CVE-2026-77883 | MEDIUM | 4.9 | — | Sep 14, 2026 | Exposure of sensitive information through data queries vulnerability in Apache Syncope. An administrator with adequate ... |
| CVE-2026-77147 | MEDIUM | 6.5 | — | Sep 14, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Syncope. An administrator with adequa... |
| CVE-2026-75015 | MEDIUM | 4.9 | — | Sep 14, 2026 | Insufficiently Protected Credentials vulnerability in Apache Syncope. Audit events, when sent to the configured store, ... |
| CVE-2026-90712 | MEDIUM | 4.3 | — | Sep 14, 2026 | A vulnerability was identified in Gitlawb openclaude up to 0.30.0. Impacted is the function waitForCallback of the file ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now