2026 CVE Vulnerabilities
64,858 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9160 | MEDIUM | 4.3 | — | Sep 11, 2026 | Improper neutralization of special elements used in a template engine vulnerability in Arma Digital Media Inc. Website T... |
| CVE-2026-89090 | MEDIUM | 5.9 | — | Sep 11, 2026 | An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allo... |
| CVE-2026-87910 | MEDIUM | 5.7 | 0.4% | Sep 11, 2026 | When tarfile extracts a link on a system that doesn't support links, it falls back to extracting a member from the archi... |
| CVE-2026-82535 | MEDIUM | 6.1 | 0.5% | Sep 11, 2026 | Chamilo LMS before 1.11.42 and 3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated at... |
| CVE-2026-81909 | MEDIUM | 5.9 | — | Sep 11, 2026 | Concrete CMS 9 through 9.5.2 is vulnerable to Missing Authorization in the block alias route (Process::alias() in concre... |
| CVE-2026-81908 | MEDIUM | 6 | — | Sep 11, 2026 | Concrete CMS 9.2.0 to 9.5.2 contain a missing authorization vulnerability in the REST API Groups list endpoint. The list... |
| CVE-2026-7298 | MEDIUM | 6.1 | 0.3% | Sep 11, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in IdeaSoft Software ... |
| CVE-2026-68528 | MEDIUM | 6 | — | Sep 11, 2026 | Concrete CMS RSS Displayer block below version 9.5.3 rendered remote feed item titles without HTML escaping, resulting ... |
| CVE-2026-18495 | MEDIUM | 6.1 | 0.1% | Sep 11, 2026 | A flaw was found in libtiff. A heap-buffer overflow vulnerability exists in the `tiff2pdf` utility due to an integer tru... |
| CVE-2026-18122 | MEDIUM | 6 | — | Sep 11, 2026 | Concrete CMS 9.2.0 to 9.5.2 Express REST API list endpoint exposes restricted Express entries via Missing Authorization;... |
| CVE-2026-18061 | MEDIUM | 5.9 | 0.3% | Sep 11, 2026 | Improper restriction of XML external entity references in the RemoteQueryCachePlugin in AWS Advanced JDBC Wrapper 3.3.0 ... |
| CVE-2026-8304 | MEDIUM | 5.5 | — | Sep 11, 2026 | Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus About allows Explo... |
| CVE-2026-89265 | MEDIUM | 4.3 | — | Sep 11, 2026 | MoguBlog through 6.2 contains an authorization bypass vulnerability in the POST /pictureSort/getPictureSortByUid endpoin... |
| CVE-2026-89264 | MEDIUM | 4.3 | — | Sep 11, 2026 | MoguBlog through 6.2 fails to validate the comment author identity in the POST /web/comment/add endpoint, allowing authe... |
| CVE-2026-89263 | MEDIUM | 5.3 | 0.3% | Sep 11, 2026 | MoguBlog through 6.2 fails to authenticate requests to the /web/comment/closeEmailNotification endpoint, allowing unauth... |
| CVE-2026-89261 | MEDIUM | 6.5 | — | Sep 11, 2026 | MoguBlog through 6.2 exposes Elasticsearch index management endpoints in the mogu_search service without authentication,... |
| CVE-2026-89012 | MEDIUM | 6.5 | 0.3% | Sep 11, 2026 | Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parame... |
| CVE-2026-81861 | MEDIUM | 5.9 | 0.4% | Sep 11, 2026 | CWE-522: Insufficiently Protected Credentials vulnerability that could result in exposure of authentication information ... |
| CVE-2026-15439 | MEDIUM | 6.5 | — | Sep 11, 2026 | The GamiPress plugin for WordPress is vulnerable to authenticated (Subscriber+) SQL Injection via the 'q' parameter of t... |
| CVE-2026-85083 | MEDIUM | 6.8 | 0.3% | Sep 11, 2026 | The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical ac... |
| CVE-2026-89298 | MEDIUM | 4.9 | 0.2% | Sep 11, 2026 | A flaw was found in the Dynamic Client Registration service of Keycloak, an open-source identity and access management s... |
| CVE-2026-57843 | MEDIUM | 5.5 | 0.1% | Sep 11, 2026 | NetBSD contains an information disclosure vulnerability in mm_open() within sys/dev/mm.c that allows unprivileged local ... |
| CVE-2026-15710 | MEDIUM | 6.8 | 0.1% | Sep 11, 2026 | An information leakage vulnerability exists in the Endpoint DLP component (epdlpdrv.sys) of Netskope Client for Windows ... |
| CVE-2026-89258 | MEDIUM | 6.3 | — | Sep 11, 2026 | Hugo is a static site generator. In versions after v0.123.0 and before v0.165.0, symlinks in parent directories were not... |
| CVE-2026-89257 | MEDIUM | 5.4 | 0.2% | Sep 11, 2026 | AVideo through 29.0 contains an insecure direct object reference (IDOR) vulnerability in objects/categoryDeleteAssets.js... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now