2026 CVE Vulnerabilities
64,704 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100741 | CRITICAL | 9.8 | — | Sep 27, 2026 | Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3... |
| CVE-2026-100721 | CRITICAL | 9 | — | Sep 27, 2026 | vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `... |
| CVE-2026-100740 | CRITICAL | 9.9 | — | Sep 27, 2026 | A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel... |
| CVE-2026-82901 | CRITICAL | 9.8 | — | Sep 26, 2026 | The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file... |
| CVE-2026-85984 | CRITICAL | 9.8 | — | Sep 26, 2026 | The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass... |
| CVE-2026-97163 | CRITICAL | 10 | — | Sep 26, 2026 | Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 |
| CVE-2026-97161 | CRITICAL | 9.2 | — | Sep 26, 2026 | Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.... |
| CVE-2026-97160 | CRITICAL | 9.4 | — | Sep 26, 2026 | Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0... |
| CVE-2026-94132 | CRITICAL | 9.5 | — | Sep 26, 2026 | Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterpri... |
| CVE-2026-94130 | CRITICAL | 9.3 | — | Sep 26, 2026 | Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injectio... |
| CVE-2026-100717 | CRITICAL | 9.9 | — | Sep 26, 2026 | froxlor is a server administration panel. In versions 2.3.10 and earlier, Validate::validateUrl rejects carriage return ... |
| CVE-2026-100716 | CRITICAL | 9.9 | — | Sep 26, 2026 | Froxlor is a server administration panel. In versions 2.3.10 and earlier, the customer data-export (DataDump) cron fails... |
| CVE-2026-100715 | CRITICAL | 9.6 | — | Sep 26, 2026 | Froxlor through 2.3.10 is vulnerable to arbitrary file deletion via symlink following in the FTP data deletion cron task... |
| CVE-2026-100714 | CRITICAL | 9.1 | — | Sep 26, 2026 | Froxlor before 2.3.12 does not restrict or escape the system.letsencryptchallengepath setting: unlike sibling settings h... |
| CVE-2026-100706 | CRITICAL | 9.9 | — | Sep 26, 2026 | kyverno before 1.19.1 fails to properly validate URL-encoded path segments in Policy apiCall urlPath, allowing namespace... |
| CVE-2026-18143 | CRITICAL | 9.8 | 0.4% | Sep 26, 2026 | The Request a Quote for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, a... |
| CVE-2026-100382 | CRITICAL | 10 | 0.9% | Sep 25, 2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Wikimedia Fo... |
| CVE-2026-97064 | CRITICAL | 9.1 | — | Sep 25, 2026 | X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the d... |
| CVE-2026-97063 | CRITICAL | 9.1 | — | Sep 25, 2026 | X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobi... |
| CVE-2026-84458 | CRITICAL | 9.1 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when the "Automatic account link on ... |
| CVE-2026-48482 | CRITICAL | 9.4 | — | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a form administrator can use Form imp... |
| CVE-2026-92161 | CRITICAL | 9.8 | — | Sep 25, 2026 | FriendsOfFlarum OAuth allows users to log in to Flarum with GitHub, Twitter, Facebook, and other providers. Prior to 1.7... |
| CVE-2026-62262 | CRITICAL | 9.1 | — | Sep 25, 2026 | Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when rating is ... |
| CVE-2026-42322 | CRITICAL | 9.1 | — | Sep 25, 2026 | Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_standard_page... |
| CVE-2026-39353 | CRITICAL | 9.1 | — | Sep 25, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1,... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now