2026 CVE Vulnerabilities
65,293 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-102010 | HIGH | 7 | — | Sep 28, 2026 | A flaw was found in GCC. When an application calls the erase_if function on a binary heap priority queue in libstdc++, t... |
| CVE-2026-101139 | LOW | 2.7 | — | Sep 28, 2026 | A vulnerability was detected in Webkul Bagisto up to 2.4.6. This impacts an unknown function of the file /admin/sales/in... |
| CVE-2026-101132 | LOW | 3.1 | — | Sep 28, 2026 | A security flaw has been discovered in DeepSeek deepseek-harness up to 0.1.7-rc.2. The affected element is the function ... |
| CVE-2026-101131 | LOW | 3.3 | — | Sep 28, 2026 | A vulnerability was identified in deepseek-ai deepseek-harness up to 0.1.5-rc.3. Impacted is an unknown function of the ... |
| CVE-2026-101111 | MEDIUM | 5.3 | — | Sep 28, 2026 | Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6 - The public book-detail... |
| CVE-2026-101110 | CRITICAL | 9.3 | — | Sep 28, 2026 | Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s ... |
| CVE-2026-101109 | MEDIUM | 5.3 | — | Sep 28, 2026 | Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) < 6.5.8 - The public vehicle-... |
| CVE-2026-101108 | CRITICAL | 9.3 | — | Sep 28, 2026 | Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 - site/vehiclemanager.... |
| CVE-2026-101105 | MEDIUM | 6.3 | — | Sep 28, 2026 | A vulnerability was determined in code-projects Matrimonial System 1.0. The affected element is the function processprof... |
| CVE-2026-100753 | MEDIUM | 5.3 | — | Sep 28, 2026 | Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9 - The public pro... |
| CVE-2026-100752 | CRITICAL | 9.3 | — | Sep 28, 2026 | Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatem... |
| CVE-2026-96740 | MEDIUM | 6.5 | — | Sep 28, 2026 | A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console cu... |
| CVE-2026-75600 | HIGH | 8.6 | — | Sep 28, 2026 | FreePBX is an open source IP PBX. Prior to version 17.0.9, authenticated users who are authorized to access the GraphQL ... |
| CVE-2026-55160 | HIGH | 7.6 | — | Sep 28, 2026 | Stringer is a self-hosted, anti-social RSS reader. Prior to commit 75cb095, an unrestricted Server-Side Request Forgery ... |
| CVE-2026-55157 | HIGH | 8.4 | — | Sep 28, 2026 | Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge gra... |
| CVE-2026-55156 | MEDIUM | 5.3 | — | Sep 28, 2026 | Token Optimizer MCP measures token savings per AI coding agent, optimizes context, and shares a live local knowledge gra... |
| CVE-2026-54710 | HIGH | 8.6 | — | Sep 28, 2026 | FreePBX is an open source IP PBX. Prior to versions 16.0.40 and 17.0.7, a critical remote code execution (RCE) vulnerabi... |
| CVE-2026-54708 | HIGH | 8.6 | — | Sep 28, 2026 | FreePBX is an open source IP PBX. Prior to versions 16.0.72 and 17.0.7, a critical vulnerability exists in the FreePBX b... |
| CVE-2026-54675 | HIGH | 8.7 | — | Sep 28, 2026 | FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, a critical vulnerability exists in the sound lan... |
| CVE-2026-54674 | HIGH | 8.6 | — | Sep 28, 2026 | FreePBX is an open source IP PBX. Prior to versions 16.0.39 and 17.0.7, users authenticated via User Control Panel (UCP)... |
| CVE-2026-49994 | CRITICAL | 9.1 | — | Sep 28, 2026 | Bluehood monitors local bluetooth activity. Prior to version 0.7.1, when auth_enabled is set in Bluehood, only the HTML ... |
| CVE-2026-45562 | HIGH | 7.7 | — | Sep 28, 2026 | FreePBX is an open source IP PBX. Prior to versions 16.0.4 and 17.0.6, the FreePBX Music on Hold (MoH) module contains a... |
| CVE-2026-101913 | MEDIUM | 6.3 | — | Sep 28, 2026 | ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.5.1, the Address... |
| CVE-2026-101912 | MEDIUM | 6.3 | — | Sep 28, 2026 | ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the isInSub... |
| CVE-2026-101911 | MEDIUM | 6.3 | — | Sep 28, 2026 | ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.7.1, the Address... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now