2026 CVE Vulnerabilities
64,909 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-90929 | HIGH | 8.1 | 0.4% | Sep 14, 2026 | File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect authorization flaw in the direct-upload endpoint (res... |
| CVE-2026-90715 | HIGH | 7.3 | — | Sep 14, 2026 | A security vulnerability has been detected in marcobambini Gravity up to 0.9.7. This affects an unknown function of the ... |
| CVE-2026-78336 | HIGH | 7.5 | — | Sep 14, 2026 | Insertion of sensitive information into sent data vulnerability in Apache Syncope. Any authenticated user can query f... |
| CVE-2026-73178 | HIGH | 7.5 | — | Sep 14, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Syncope. An administrator with adequ... |
| CVE-2026-90710 | HIGH | 7.3 | 0.5% | Sep 14, 2026 | A vulnerability was determined in taisan tarzan-cms 1.0.0. This issue affects the function openConnection of the file co... |
| CVE-2026-90708 | HIGH | 7.3 | 0.3% | Sep 14, 2026 | A weakness has been identified in Yot CMS up to 3.3.1. Affected by this vulnerability is the function Login of the file ... |
| CVE-2026-90707 | HIGH | 8.3 | — | Sep 14, 2026 | A security flaw has been discovered in Open5GS up to 2.7.x. Affected is the function amf_nnrf_try_old_amf_discovery_fall... |
| CVE-2026-8821 | HIGH | 7.1 | 0.2% | Sep 14, 2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel m... |
| CVE-2026-89180 | HIGH | 7.5 | 0.3% | Sep 14, 2026 | EFence developed by Thinking Software Technology has a SQL Injection vulnerability, allowing unauthenticated remote atta... |
| CVE-2026-87779 | HIGH | 7.5 | — | Sep 14, 2026 | Insertion of sensitive information into log file vulnerability in Apache Syncope. When AES key of non-standard length... |
| CVE-2026-81564 | HIGH | 7 | 0.3% | Sep 14, 2026 | Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP P... |
| CVE-2026-78375 | HIGH | 8.6 | 0.2% | Sep 14, 2026 | Joomla Extension - joomshaper.com - Authenticated Privileged SQL Injection in the Content Plugin of SP Page Builder (Fre... |
| CVE-2026-20773 | HIGH | 8.5 | 0.2% | Sep 14, 2026 | A role-based access control issue was identified in the administrative expression evaluation functionality. This could a... |
| CVE-2026-90895 | HIGH | 8.4 | 0.2% | Sep 14, 2026 | Affected versions of MISP’s interactive CLI shell implement access control independently from the normal web application... |
| CVE-2026-90894 | HIGH | 7.8 | 0.1% | Sep 14, 2026 | Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_s... |
| CVE-2026-90701 | HIGH | 7.3 | — | Sep 14, 2026 | A vulnerability was detected in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee693dc4d9a29a... |
| CVE-2026-72524 | HIGH | 8.8 | — | Sep 14, 2026 | Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access... |
| CVE-2026-12518 | HIGH | 8.5 | 0.1% | Sep 14, 2026 | A local privilege escalation vulnerability in the Logitech Logi Options+ updater service on Windows allows a low-privile... |
| CVE-2026-90691 | HIGH | 8.3 | 0.4% | Sep 14, 2026 | A security vulnerability has been detected in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The imp... |
| CVE-2026-90690 | HIGH | 7.3 | 1.4% | Sep 14, 2026 | A weakness has been identified in 0x4m4 HexStrike AI up to d689933ff579d839c676c82b231f8e98326c5f04. The affected elemen... |
| CVE-2026-90689 | HIGH | 8.8 | 0.6% | Sep 14, 2026 | A security flaw has been discovered in Tenda W20E 15.11.0.61068_1546_841_CN_TDC. Impacted is the function formDelWebAuth... |
| CVE-2026-88853 | HIGH | 7.5 | 0.2% | Sep 14, 2026 | Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla <... |
| CVE-2026-88852 | HIGH | 7.5 | 0.2% | Sep 14, 2026 | Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free extension for Joomla < 7.0.0,... |
| CVE-2026-85195 | HIGH | 7.5 | 0.2% | Sep 14, 2026 | Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 2... |
| CVE-2026-85191 | HIGH | 7.5 | 0.2% | Sep 14, 2026 | Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joom... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now