2026 CVE Vulnerabilities
64,734 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93030 | MEDIUM | 6.5 | — | Sep 25, 2026 | FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity in... |
| CVE-2026-97864 | MEDIUM | 5.3 | — | Sep 25, 2026 | A vulnerability has been found in GibbonEdu Gibbon up to 30.0.01. The affected element is the function makeBlock of the ... |
| CVE-2026-97222 | MEDIUM | 5.5 | — | Sep 25, 2026 | A heap use-after-free flaw was found in Gnumeric. When a user opens a crafted Gnumeric workbook containing a malformed S... |
| CVE-2026-80431 | MEDIUM | 6.8 | — | Sep 25, 2026 | Out-of-bounds Write in the natural width branch of the text sizing protocol in kitty from 0.40.0 before 0.49.0 allows a ... |
| CVE-2026-80430 | MEDIUM | 4.6 | — | Sep 25, 2026 | Improper Link Resolution Before File Access in the drag source staging path of the drag and drop protocol in kitty from ... |
| CVE-2026-100190 | MEDIUM | 6.3 | — | Sep 25, 2026 | The AIL Framework crawler splash domain page (showDomain.html) is vulnerable to stored cross-site script injection (XSS)... |
| CVE-2026-100187 | MEDIUM | 6.9 | — | Sep 25, 2026 | The Onion module in AIL Framework contained a performance shortcut in its URL extraction logic that accepted URLs as val... |
| CVE-2026-100177 | MEDIUM | 6.3 | — | Sep 25, 2026 | The AIL Framework crawler task creation API (api_add_crawler_task) contained an insufficient authorization check when a ... |
| CVE-2026-100174 | MEDIUM | 5.1 | — | Sep 25, 2026 | The AIL Framework tag selector component (var/www/static/js/tags.js) is vulnerable to stored cross-site scripting (XSS).... |
| CVE-2026-78902 | MEDIUM | 6.1 | — | Sep 25, 2026 | Cross Site Scripting vulnerability in Netgate pfSense 26.03.1-RELEASE allows an attacker to execute arbitrary code via t... |
| CVE-2026-27867 | MEDIUM | 4.8 | — | Sep 25, 2026 | An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, registration actio... |
| CVE-2026-97863 | MEDIUM | 6.3 | 0.3% | Sep 25, 2026 | The cisco_firesight_manager_ACL_rule_export module in misp-modules generates a shell script (.sh) that authenticates to ... |
| CVE-2026-92573 | MEDIUM | 6.5 | — | Sep 25, 2026 | Improper handling of compressed data in the shared GZIP decompressor used for AMQP 0-8/0-9/0-9-1 and AMQP 0-10 message d... |
| CVE-2026-88848 | MEDIUM | 4.2 | — | Sep 25, 2026 | The MasterStudy LMS WordPress plugin from 1.9 before 3.7.50 does not verify that a course a member asks to enrol in is c... |
| CVE-2026-86837 | MEDIUM | 5.3 | — | Sep 25, 2026 | The Bookly WordPress plugin before 28.3 does not properly verify a customer's identity before updating their stored deta... |
| CVE-2026-80514 | MEDIUM | 5.3 | — | Sep 25, 2026 | The wpForo Forum WordPress plugin from 3.0.0 before 3.1.6 does not verify the source of client-supplied IP address heade... |
| CVE-2026-6088 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-6087 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-6086 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-6085 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-6084 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-6083 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-6082 | MEDIUM | 5.1 | — | Sep 25, 2026 | Stored Cross-Site Scripting (XSS) vulnerability in StockAgile API and management panel. The vulnerability is present on ... |
| CVE-2026-96448 | MEDIUM | 6.6 | 0.2% | Sep 25, 2026 | A flaw was found in the Fine-Grained Admin Permissions (FGAP v2) feature of Keycloak, an identity and access management ... |
| CVE-2026-93747 | MEDIUM | 6.4 | — | Sep 25, 2026 | The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'telegram' profile field in v... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now