2026 CVE Vulnerabilities
64,868 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-88790 | MEDIUM | 4.8 | — | Sep 10, 2026 | A security vulnerability has been detected in proma-ai Proma up to 0.19.37. Affected is the function resolveTargetPath o... |
| CVE-2026-45763 | MEDIUM | 5.9 | — | Sep 10, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. St... |
| CVE-2026-12683 | MEDIUM | 5.4 | 0.2% | Sep 10, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation... |
| CVE-2026-12682 | MEDIUM | 5.4 | 0.2% | Sep 10, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Ankaref Innovation... |
| CVE-2026-9161 | MEDIUM | 5.3 | — | Sep 10, 2026 | Observable response discrepancy vulnerability in DernekPlus Website Template allows Account Footprinting. This issue af... |
| CVE-2026-88038 | MEDIUM | 4.8 | — | Sep 10, 2026 | cookies is a Node.js library for reading and writing HTTP cookies, used by Koa via ctx.cookies. In versions before 0.9.2... |
| CVE-2026-85544 | MEDIUM | 6.1 | 0.1% | Sep 10, 2026 | Some Hikvision intercom products utilize an immutable factory value which should be obtained from local network or physi... |
| CVE-2026-85543 | MEDIUM | 4.3 | — | Sep 10, 2026 | Some Wi-Fi series camera products have insufficient permission validation on certain interfaces, allowing authenticated ... |
| CVE-2026-17038 | MEDIUM | 6.9 | — | Sep 10, 2026 | DrEryk Gabinet before 11.5.0 uses hard-coded API credentials in its ticket reporting component. These credentials can be... |
| CVE-2026-88859 | MEDIUM | 6.3 | — | Sep 10, 2026 | A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML emai... |
| CVE-2026-84828 | MEDIUM | 6.5 | 0.1% | Sep 10, 2026 | A flaw was found in PCS (Pacemaker Configuration System). A local attacker with membership in the 'haclient' group can e... |
| CVE-2026-78085 | MEDIUM | 6.9 | — | Sep 10, 2026 | Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4 - The gallery mana... |
| CVE-2026-78374 | MEDIUM | 6.9 | 0.5% | Sep 10, 2026 | Joomla Extension - joomlart.com - Open mail relay via contact AJAX endpoint in T4 Page Builder extension < 2.3.0 - The f... |
| CVE-2026-78303 | MEDIUM | 6.9 | 0.4% | Sep 10, 2026 | Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property... |
| CVE-2026-78084 | MEDIUM | 6.9 | 0.3% | Sep 10, 2026 | Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in SP Property < 4.1.4 - The gal... |
| CVE-2026-5399 | MEDIUM | 6.4 | 0.3% | Sep 10, 2026 | The Redux Framework plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Slider field in User Profi... |
| CVE-2026-15889 | MEDIUM | 6.4 | 0.3% | Sep 10, 2026 | The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Content in all ve... |
| CVE-2026-88288 | MEDIUM | 6.5 | 0.4% | Sep 10, 2026 | GeoVision GV-LPC2211 V1.13 fails to restrict the filename supplied to BKDownloadLink.cgi, allowing a remote user with va... |
| CVE-2026-88284 | MEDIUM | 4.9 | 0.3% | Sep 10, 2026 | GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF SetUser requests, allowing an authenticated ad... |
| CVE-2026-88283 | MEDIUM | 4.9 | 0.3% | Sep 10, 2026 | GeoVision GV-LPC2211 V1.13 fails to limit repeated User elements in ONVIF CreateUsers requests, allowing an authenticate... |
| CVE-2026-88281 | MEDIUM | 4.9 | 0.3% | Sep 10, 2026 | GeoVision GV-LPC2211 V1.13 fails to limit repeated Username elements in ONVIF DeleteUsers requests, allowing an authenti... |
| CVE-2026-88280 | MEDIUM | 4.9 | 0.3% | Sep 10, 2026 | GeoVision GV-LPC2211 V1.13 copies an oversized ONVIF SetUser password into a fixed stack field, allowing an authenticate... |
| CVE-2026-88279 | MEDIUM | 4.9 | 0.3% | Sep 10, 2026 | GeoVision GV-LPC2211 V1.13 copies oversized ONVIF CreateUsers username or password values into fixed stack fields, allow... |
| CVE-2026-88270 | MEDIUM | 6.5 | 0.2% | Sep 10, 2026 | GeoVision GV-LPC2211 V1.13 allows a Guest user to enter SSVR firmware-upgrade mode and disrupt live services before any ... |
| CVE-2026-88269 | MEDIUM | 6.5 | 0.2% | Sep 10, 2026 | GeoVision GV-LPC2211 V1.13 allows a Guest user to retrieve persistent device configuration containing plaintext administ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now