2026 CVE Vulnerabilities
64,868 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-88268 | MEDIUM | 6.5 | 0.2% | Sep 10, 2026 | GeoVision GV-LPC2211 V1.13 contains an authenticated stack buffer overflow in SSVR fragment reassembly that allows a val... |
| CVE-2026-88265 | MEDIUM | 5.6 | 0.1% | Sep 10, 2026 | A flaw was found in crun. After pivot_root, reopening /dev/null for stdio can follow a symlink and attach a host file to... |
| CVE-2026-88264 | MEDIUM | 5.6 | 0.1% | Sep 10, 2026 | A flaw was found in crun. When the container configuration does not give /dev a dedicated mount, terminal setup can redi... |
| CVE-2026-42808 | MEDIUM | 6.8 | 0.2% | Sep 10, 2026 | An issue was discovered in Bosch Sensortec COINES_SDK versions 2.0 through 2.11. The host streaming API function {{c... |
| CVE-2026-42806 | MEDIUM | 4.3 | 0.2% | Sep 10, 2026 | An out-of-bounds read vulnerability was discovered in the Bosch BME690 SensorAPI (C-driver) in version v1.0.3 and prior,... |
| CVE-2026-88770 | MEDIUM | 6.5 | 0.2% | Sep 10, 2026 | A flaw was found in the Device Authorization Grant flow of Keycloak, an identity and access management solution. The iss... |
| CVE-2026-88763 | MEDIUM | 5.9 | 0.3% | Sep 10, 2026 | A flaw was found in the skupper-router component of Red Hat Service Interconnect, which is used to provide secure commun... |
| CVE-2026-82582 | MEDIUM | 5.3 | 0.2% | Sep 10, 2026 | An authorization bypass vulnerability exists in SHIRASAGI through a user-controlled key, which may allow an unauthorized... |
| CVE-2026-81635 | MEDIUM | 5.1 | 0.2% | Sep 10, 2026 | A cross-site scripting vulnerability exists in SHIRASAGI, which may allow an attacker to execute an arbitrary script in ... |
| CVE-2026-19840 | MEDIUM | 6.5 | 0.1% | Sep 10, 2026 | The Notiqoo WordPress plugin before 1.4.14 does not have capability checks on several of its AJAX actions and builds th... |
| CVE-2026-0304 | MEDIUM | 4.8 | 0.2% | Sep 10, 2026 | A privilege escalation vulnerability in Palo Alto Networks Cortex XDR Broker VM enables an authenticated low privileged ... |
| CVE-2026-85645 | MEDIUM | 6.1 | 0.2% | Sep 10, 2026 | The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Reflect... |
| CVE-2026-0309 | MEDIUM | 4 | 0.4% | Sep 10, 2026 | A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypas... |
| CVE-2026-0307 | MEDIUM | 5.9 | 0.1% | Sep 10, 2026 | Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allows a local user to ... |
| CVE-2026-0306 | MEDIUM | 5.8 | 0.1% | Sep 10, 2026 | A vulnerability in the EndPoint Data Loss Prevention (DLP) enforcement of Palo Alto Networks Prisma® Access Agent enable... |
| CVE-2026-0305 | MEDIUM | 4.3 | 0.1% | Sep 10, 2026 | An information disclosure vulnerability in the Palo Alto Networks Prisma® Access Agent on Linux enables a local user to ... |
| CVE-2026-75880 | MEDIUM | 6.5 | 0.4% | Sep 10, 2026 | An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excess... |
| CVE-2026-57822 | MEDIUM | 6.5 | 0.3% | Sep 10, 2026 | When the broker is processing message-based management requests, sent by an authenticated messaging client that is autho... |
| CVE-2026-4657 | MEDIUM | 6.4 | 0.2% | Sep 10, 2026 | The Easy Google Fonts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the control_selectors meta f... |
| CVE-2026-18594 | MEDIUM | 4.3 | 0.2% | Sep 10, 2026 | The Advanced Contact form 7 DB plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inc... |
| CVE-2026-18386 | MEDIUM | 4.9 | 0.7% | Sep 10, 2026 | The WP BackItUp Community Edition plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and i... |
| CVE-2026-15823 | MEDIUM | 4.3 | 0.2% | Sep 10, 2026 | The Builderall Cheetah For Wp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing c... |
| CVE-2026-15820 | MEDIUM | 6.4 | 0.2% | Sep 10, 2026 | The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Photo Module 'attribu... |
| CVE-2026-15796 | MEDIUM | 6.4 | 0.2% | Sep 10, 2026 | The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'bg_video_service_url... |
| CVE-2026-87870 | MEDIUM | 6.4 | 0.2% | Sep 10, 2026 | The Ninja Forms - Scheduled Exports plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API Param... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now