2026 CVE Vulnerabilities
64,889 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-89023 | HIGH | 8.6 | — | Sep 14, 2026 | ThemeAtelier Domain For Sale plugin for WordPress before 3.5.2 contains a missing authorization vulnerability in its RES... |
| CVE-2026-86830 | HIGH | 7.2 | — | Sep 14, 2026 | Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution befor... |
| CVE-2026-82049 | HIGH | 8.4 | 0.2% | Sep 14, 2026 | In CPython 3.13 and earlier, the tarfile module's data and tar extraction filters are vulnerable to crafted archives con... |
| CVE-2026-82035 | HIGH | 7.1 | 0.5% | Sep 14, 2026 | PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path traversal vulnerability in the font branch of extract_o... |
| CVE-2026-77884 | HIGH | 7.1 | 0.3% | Sep 14, 2026 | Gallery - Private Photo Vault 1.0.41 starts an unauthenticated HTTP server that is reachable from the local network. The... |
| CVE-2026-91080 | HIGH | 7.5 | 0.6% | Sep 14, 2026 | webhook through 2.8.3 reads the entire request body into memory before evaluating trigger rules, allowing unauthenticate... |
| CVE-2026-91079 | HIGH | 8.5 | 0.4% | Sep 14, 2026 | Huly Platform through 0.7.426 contains a server-side request forgery vulnerability in the print service due to missing h... |
| CVE-2026-90946 | HIGH | 7.5 | 0.6% | Sep 14, 2026 | DeepWiki-Open through commit d92819a contains an arbitrary file read vulnerability in the unauthenticated /ws/chat WebSo... |
| CVE-2026-90944 | HIGH | 8.2 | 0.7% | Sep 14, 2026 | Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenti... |
| CVE-2026-90805 | HIGH | 7.3 | 0.3% | Sep 14, 2026 | A flaw has been found in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a578. Th... |
| CVE-2026-86836 | HIGH | 8.4 | 0.1% | Sep 14, 2026 | In Eclipse Ankaios versions 0.1.0 through 1.0.2, the agent creates workload files and Control Interface named pipes (FIF... |
| CVE-2026-85921 | HIGH | 8.2 | 0.3% | Sep 14, 2026 | Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally. |
| CVE-2026-85892 | HIGH | 7.8 | 0.2% | Sep 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Edge (Chromium-... |
| CVE-2026-73494 | HIGH | 7.4 | — | Sep 14, 2026 | blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and from 1.0.... |
| CVE-2026-70658 | HIGH | 7.4 | — | Sep 14, 2026 | Pay is a payments engine for Ruby on Rails 6.0 and higher. Prior to 11.6.2, Pay::Webhooks::PaddleBillingController#valid... |
| CVE-2026-57577 | HIGH | 8.2 | — | Sep 14, 2026 | DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, a rout... |
| CVE-2026-55253 | HIGH | 7.7 | — | Sep 14, 2026 | LangChain MongoDB provides integrations between MongoDB, Atlas, LangChain, and LangGraph. Prior to langgraph-checkpoint-... |
| CVE-2026-55091 | HIGH | 7.5 | — | Sep 14, 2026 | flat-to-nested converts a hierarchy from a flat representation to a nested representation. Prior to 1.1.2, FlatToNested.... |
| CVE-2026-54567 | HIGH | 7.5 | 0.6% | Sep 14, 2026 | Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flask... |
| CVE-2026-54182 | HIGH | 8.1 | — | Sep 14, 2026 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha... |
| CVE-2026-54180 | HIGH | 7.6 | — | Sep 14, 2026 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha... |
| CVE-2026-54178 | HIGH | 8.1 | 0.4% | Sep 14, 2026 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha... |
| CVE-2026-54175 | HIGH | 7.6 | — | Sep 14, 2026 | backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages tha... |
| CVE-2026-54087 | HIGH | 7.6 | — | Sep 14, 2026 | EasyAdmin is a fast and modern admin generator for Symfony applications. From 5.0.0 until 5.0.13, FileField and ImageFie... |
| CVE-2026-53752 | HIGH | 7.5 | 0.4% | Sep 14, 2026 | docx4j is an open source Java library for creating, editing, and saving OpenXML packages, including DOCX, PPTX, and XLSX... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now