2026 CVE Vulnerabilities
64,734 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-67230 | MEDIUM | 6.3 | — | Sep 25, 2026 | RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the Web STOMP WebSoc... |
| CVE-2026-67227 | MEDIUM | 5.9 | — | Sep 25, 2026 | RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.22 and 4.1.14 and 4.2.7 and 4.3.1, Atom exhaustion: t... |
| CVE-2026-67226 | MEDIUM | 6.9 | — | Sep 25, 2026 | RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.0.22 and 4.1.14 and 4.2.7, Admin-only atom exhaustion: ... |
| CVE-2026-67225 | MEDIUM | 6.3 | — | Sep 25, 2026 | RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the stream protocol ... |
| CVE-2026-67223 | MEDIUM | 6.3 | — | Sep 25, 2026 | RabbitMQ is a messaging and streaming broker. The advisory establishes affected 3.13, 4.0, 4.1, 4.2, and 4.3 maintenance... |
| CVE-2026-67222 | MEDIUM | 5.9 | — | Sep 25, 2026 | RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15, 4.0.20, 4.1.11, and 4.2.6, mechanisms/1 applied... |
| CVE-2026-66073 | MEDIUM | 6 | — | Sep 25, 2026 | RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.20 and 4.1.11 and 4.2.6, Atom table exha... |
| CVE-2026-66071 | MEDIUM | 6 | — | Sep 25, 2026 | RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.22 and 4.1.11 and 4.2.6 and 4.3.1, Atom ... |
| CVE-2026-61837 | MEDIUM | 6.3 | — | Sep 25, 2026 | RabbitMQ is a messaging and streaming broker. From 4.0.0 until 4.3.3, 4.2.9, 4.1.14, and 4.0.23, AMQP 1.0 management GET... |
| CVE-2026-18320 | MEDIUM | 6.1 | — | Sep 25, 2026 | Readwise Reader for Android uses a sanitize-html configuration that permits all attributes on SVG and PATH elements due ... |
| CVE-2026-18312 | MEDIUM | 6.1 | — | Sep 25, 2026 | Readwise Reader for Android constructs URLs in its WebView using attacker-controlled metadata without proper encoding or... |
| CVE-2026-18311 | MEDIUM | 6.1 | — | Sep 25, 2026 | Readwise Reader for Android contains a cross-site scripting vulnerability due to missing HTML sanitization in its proces... |
| CVE-2026-100237 | MEDIUM | 6.1 | — | Sep 25, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foun... |
| CVE-2026-97869 | MEDIUM | 4.1 | — | Sep 25, 2026 | A flaw has been found in langchain4j up to 1.5.3-beta10/1.11.10-beta18/1.18.1-beta27. This vulnerability affects the fun... |
| CVE-2026-97469 | MEDIUM | 4.3 | — | Sep 25, 2026 | PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to repeatedly call the anon.hash() ... |
| CVE-2026-85293 | MEDIUM | 4.8 | — | Sep 25, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2-bet... |
| CVE-2026-85292 | MEDIUM | 4.8 | — | Sep 25, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo... |
| CVE-2026-85291 | MEDIUM | 6.5 | — | Sep 25, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo... |
| CVE-2026-85290 | MEDIUM | 5.3 | — | Sep 25, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo... |
| CVE-2026-85289 | MEDIUM | 6.5 | — | Sep 25, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo... |
| CVE-2026-85274 | MEDIUM | 6.5 | — | Sep 25, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo... |
| CVE-2026-54790 | MEDIUM | 6 | — | Sep 25, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo... |
| CVE-2026-39372 | MEDIUM | 4.9 | — | Sep 25, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo... |
| CVE-2026-100230 | MEDIUM | 5.3 | — | Sep 25, 2026 | Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, m... |
| CVE-2026-97866 | MEDIUM | 5.6 | — | Sep 25, 2026 | A weakness has been identified in Zhonglun CloudPOS 3.0. Affected by this vulnerability is an unknown functionality of t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now