2026 CVE Vulnerabilities
64,868 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84062 | MEDIUM | 5.3 | 0.3% | Sep 10, 2026 | BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass through user-controlled key. If this vulner... |
| CVE-2026-87926 | MEDIUM | 4.3 | 0.3% | Sep 10, 2026 | A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This issue... |
| CVE-2026-87924 | MEDIUM | 6.5 | 0.4% | Sep 9, 2026 | A security vulnerability has been detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c... |
| CVE-2026-87923 | MEDIUM | 4.3 | 0.3% | Sep 9, 2026 | A weakness has been identified in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. A... |
| CVE-2026-15460 | MEDIUM | 5.4 | 0.2% | Sep 9, 2026 | The Bluetooth Classic (BR/EDR) L2CAP receive handler bt_l2cap_br_recv() in subsys/bluetooth/host/classic/l2cap_br.c disp... |
| CVE-2026-88002 | MEDIUM | 6.5 | 0.3% | Sep 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.1, the messa... |
| CVE-2026-88001 | MEDIUM | 5 | 0.3% | Sep 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 until 0.11.1, server-si... |
| CVE-2026-88000 | MEDIUM | 6.5 | 0.3% | Sep 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /... |
| CVE-2026-87997 | MEDIUM | 4.3 | 0.2% | Sep 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, POST /ap... |
| CVE-2026-87994 | MEDIUM | 4.3 | 0.2% | Sep 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 until 0.11.1, the chann... |
| CVE-2026-87017 | MEDIUM | 4.3 | 0.2% | Sep 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.1, the built... |
| CVE-2026-75308 | MEDIUM | 6.1 | 0.1% | Sep 9, 2026 | yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS). The file upload endpoint /api/upload of the system lacks fi... |
| CVE-2026-75307 | MEDIUM | 6.1 | 0.1% | Sep 9, 2026 | zhitan-ems 1.0.0 is vulnerable to Cross Site Scripting (XSS) via SVG file upload through the /equipmentFile/upload endpo... |
| CVE-2026-71807 | MEDIUM | 4.3 | 0.2% | Sep 9, 2026 | In RuoYi-Cloud-Plus <= 2.6.2 in the ruoyi-workflow module, multiple core task APIs in FlwTaskController lack permission ... |
| CVE-2026-87015 | MEDIUM | 6.8 | 0.3% | Sep 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 until 0.11.1, backend/... |
| CVE-2026-87014 | MEDIUM | 6.5 | 0.3% | Sep 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, role sync... |
| CVE-2026-87013 | MEDIUM | 4.3 | 0.3% | Sep 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, POST /ap... |
| CVE-2026-87012 | MEDIUM | 4.3 | 0.3% | Sep 9, 2026 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.1, backend/o... |
| CVE-2026-79522 | MEDIUM | 6.5 | 0.2% | Sep 9, 2026 | An out-of-bounds read in the gf_dm_get_chunk_data function (src/utils/downloader.c) of GPAC v26.07.0 allows attackers to... |
| CVE-2026-79516 | MEDIUM | 4 | 0.1% | Sep 9, 2026 | An out-of-bounds read in the stbsp_vsnprintf function (stb_sprintf.h) of nothings stb commit 31c1ad3 allows attackers to... |
| CVE-2026-79515 | MEDIUM | 4.3 | 0.2% | Sep 9, 2026 | An out-of-bounds read in the stbtt_GetGlyphShape component of nothings stb commit 31c1ad3 allows attackers to cause a De... |
| CVE-2026-79514 | MEDIUM | 6.5 | 0.2% | Sep 9, 2026 | An out-of-bounds read in the gf_dm_data_received function (downloader.c) of GPAC v26.07.0 allows attackers to cause a De... |
| CVE-2026-79513 | MEDIUM | 6.5 | 0.2% | Sep 9, 2026 | A divide-by-zero vulnerability in the gf_dash_get_timeline_duration function (src/media_tools/dash_client.c) of GPAC v26... |
| CVE-2026-79387 | MEDIUM | 4.3 | 0.3% | Sep 9, 2026 | SQL injection vulnerability in PbootCMS versions 3.2.0 through 3.2.5 allows an authenticated user to modify arbitrary us... |
| CVE-2026-71803 | MEDIUM | 5.4 | 0.2% | Sep 9, 2026 | money-pos 1.0 contains a stored Cross-Site Scripting (XSS) vulnerability. When processing returns, the backend fails to ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now