2026 CVE Vulnerabilities
64,704 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100867 | LOW | 3.3 | — | Sep 27, 2026 | spaceship-prompt through 4.22.5 fails to sanitize control characters from project manifest version fields before renderi... |
| CVE-2026-100866 | LOW | 3.3 | — | Sep 27, 2026 | onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, ... |
| CVE-2026-94417 | LOW | 2.3 | — | Sep 27, 2026 | When an application enables both OCSP and CRL revocation checking on one WOLFSSL_CTX or certificate manager, wolfSSL ski... |
| CVE-2026-15442 | LOW | 2.3 | — | Sep 27, 2026 | In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS ... |
| CVE-2026-94419 | LOW | 2.3 | — | Sep 27, 2026 | Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of th... |
| CVE-2026-94418 | LOW | 2.3 | — | Sep 27, 2026 | Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate signature check separately from the parse t... |
| CVE-2026-100837 | LOW | 3.7 | — | Sep 27, 2026 | Contrast (Edgeless Systems) through 1.20.0 performs unanchored suffix matching when selecting per-registry configuration... |
| CVE-2026-100649 | LOW | 3.7 | — | Sep 26, 2026 | vLLM before 0.29.0 contains a resource-limit bypass vulnerability in PyNvVideoCodec decoder allocation where sampler sub... |
| CVE-2026-100620 | LOW | 3.8 | — | Sep 26, 2026 | Capgo CLI (npm package @capgo/cli) through 7.98.2 is affected by an over-permissioned service account in its Android onb... |
| CVE-2026-100311 | LOW | 3.5 | — | Sep 26, 2026 | A vulnerability was identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be... |
| CVE-2026-96526 | LOW | 2.7 | 0.1% | Sep 26, 2026 | The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an object-level authorization check on one ... |
| CVE-2026-96525 | LOW | 2.7 | 0.1% | Sep 26, 2026 | The MCP Server for WordPress WordPress plugin before 1.8.2 does not perform an ownership or sufficient capability check... |
| CVE-2026-100573 | LOW | 3.3 | — | Sep 26, 2026 | OpenClaw versions before 2026.8.1 contain a sandbox policy bypass vulnerability in the MCP loopback component that allow... |
| CVE-2026-100542 | LOW | 3.1 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') versions >= 2026.5.28 and < 2026.8.1 mishandle archive listings in the tar.bz2 skill i... |
| CVE-2026-100539 | LOW | 2.6 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') before 2026.8.1 fails to revoke memory tool access when an operator hot-disables memor... |
| CVE-2026-100537 | LOW | 3.1 | — | Sep 26, 2026 | OpenClaw (npm package 'openclaw') before 2026.8.1 fails to apply the originating requester's effective tool policy durin... |
| CVE-2026-100534 | LOW | 3.1 | — | Sep 26, 2026 | OpenClaw versions before 2026.8.1 contain an authorization bypass vulnerability in webhook TaskFlow cancellation that al... |
| CVE-2026-100503 | LOW | 3.3 | — | Sep 26, 2026 | Ghidra versions through 12.1.4 contain a heap use-after-free vulnerability in the decompiler's Funcdata::opInsertAfter f... |
| CVE-2026-100417 | LOW | 3.1 | — | Sep 25, 2026 | RustDesk before 1.5.0 on Windows fails to enforce the one-way file transfer option against peer clipboard file requests,... |
| CVE-2026-97897 | LOW | 3.5 | — | Sep 25, 2026 | A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the... |
| CVE-2026-97896 | LOW | 3.5 | — | Sep 25, 2026 | A vulnerability was identified in krayin laravel-crm up to 2.2.5. This vulnerability affects the function ConfigurationF... |
| CVE-2026-63204 | LOW | 2.3 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, an authenticated user with agent per... |
| CVE-2026-65828 | LOW | 2.3 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the legacy destroy_form action on At... |
| CVE-2026-56730 | LOW | 2.1 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, an authorization bypass vulnerabilit... |
| CVE-2026-67420 | LOW | 2.3 | — | Sep 25, 2026 | RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.19, 4.0.24, 4.1.15, 4.2.10, and 4.3.5, RabbitMQ OAu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now