2026 CVE Vulnerabilities
64,909 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-90770 | HIGH | 8.8 | 0.7% | Sep 13, 2026 | Spug through 3.4.0 contains a remote code execution vulnerability in the ping_check function that interpolates user-supp... |
| CVE-2026-90769 | HIGH | 7.7 | 0.4% | Sep 13, 2026 | Open Notebook before 1.11.0 fails to validate the URL parameter in POST /api/sources endpoint, allowing authenticated us... |
| CVE-2026-90768 | HIGH | 8.1 | 0.2% | Sep 13, 2026 | CAPEv2 through commit 471ee4b fails to validate task ownership in REST API endpoints, allowing authenticated users to re... |
| CVE-2026-90562 | HIGH | 8.1 | 0.4% | Sep 13, 2026 | LangBot before 4.10.11 generates password recovery keys with only 24 bits of entropy and applies no rate limiting to the... |
| CVE-2026-90561 | HIGH | 8.7 | 0.4% | Sep 13, 2026 | Strapi versions 4.x through 4.26.2 and 5.x before 5.48.1 contain a stored cross-site scripting vulnerability in the cont... |
| CVE-2026-90514 | HIGH | 7.3 | 0.3% | Sep 13, 2026 | A vulnerability has been found in SourceCodester School Registration and Fee System 1.0. Impacted is an unknown function... |
| CVE-2026-90510 | HIGH | 8.3 | 0.3% | Sep 13, 2026 | A security vulnerability has been detected in dromara orion-visor up to 2.5.7. This affects the function HostKeyServiceI... |
| CVE-2026-90509 | HIGH | 7.3 | 0.3% | Sep 13, 2026 | A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspec... |
| CVE-2026-90504 | HIGH | 7.3 | 0.6% | Sep 13, 2026 | A vulnerability has been found in vvbbnn00 WARP-Clash-API up to c7bf2360073959861219b422e51ae86411051b46. The impacted e... |
| CVE-2026-90498 | HIGH | 7.3 | 0.3% | Sep 13, 2026 | A vulnerability was identified in lenve vhr 1.0-SNAPSHOT. Affected by this issue is some unknown functionality of the fi... |
| CVE-2026-89080 | HIGH | 7.5 | 0.2% | Sep 13, 2026 | The Really Simple Security WordPress plugin before 9.8.1 does not prevent an unauthenticated request from resetting an ... |
| CVE-2026-86406 | HIGH | 7.5 | 0.2% | Sep 13, 2026 | The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a mem... |
| CVE-2026-80071 | HIGH | 7.2 | 0.3% | Sep 13, 2026 | The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership... |
| CVE-2026-90678 | HIGH | 7.5 | 0.5% | Sep 13, 2026 | An issue was discovered in HAProxy 3.3.0 through 3.4.4 and in 3.5-dev1 through 3.5-dev5. Exploitation requires an HTTP/3... |
| CVE-2026-90495 | HIGH | 7.3 | 0.3% | Sep 13, 2026 | A vulnerability has been found in Fengoffice Feng Office up to 3.11.13.11. This impacts the function Contacts::instance-... |
| CVE-2026-90493 | HIGH | 8.8 | 0.1% | Sep 13, 2026 | A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is ... |
| CVE-2026-90668 | HIGH | 7.5 | 0.3% | Sep 13, 2026 | The webserver in UnrealIRCd 6.0.5 through 6.2.6 before 6.2.7 does not limit the number of HTTP request headers, which al... |
| CVE-2026-90651 | HIGH | 8.1 | 0.2% | Sep 13, 2026 | Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certific... |
| CVE-2026-90648 | HIGH | 7.1 | 0.1% | Sep 13, 2026 | wasm2c in WebAssembly wabt through 1.0.41 allows sandbox escape in some situations that primarily involve 32-bit platfor... |
| CVE-2026-90647 | HIGH | 7.4 | 0.1% | Sep 12, 2026 | ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation... |
| CVE-2026-90616 | HIGH | 7.4 | 0.2% | Sep 12, 2026 | In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, whi... |
| CVE-2026-90560 | HIGH | 8.2 | 0.6% | Sep 12, 2026 | zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress construct... |
| CVE-2026-90559 | HIGH | 7.5 | 0.6% | Sep 12, 2026 | snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) ... |
| CVE-2026-90556 | HIGH | 7.8 | 0.1% | Sep 12, 2026 | Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with decl... |
| CVE-2026-90554 | HIGH | 7.5 | 0.2% | Sep 12, 2026 | vLLM versions >=0.10.2 and <0.28.0 do not apply any audio decode-size or duration limit when extracting audio from video... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now