2026 CVE Vulnerabilities
64,751 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-78397 | MEDIUM | 4 | — | Sep 25, 2026 | The Link Library WordPress plugin before 7.9.6 does not validate the destination of a user-supplied URL before falling b... |
| CVE-2026-78394 | MEDIUM | 4.1 | — | Sep 25, 2026 | The Link Library WordPress plugin before 7.9.6 does not sanitize a user-supplied destination folder before writing a gen... |
| CVE-2026-78393 | MEDIUM | 6.1 | — | Sep 25, 2026 | The Link Library WordPress plugin before 7.9.6 does not properly escape some parameters before outputting them in the ad... |
| CVE-2026-19775 | MEDIUM | 4.3 | — | Sep 25, 2026 | The OpenStation — Desktop Windows, Dock & Virtual Desktops for WP Admin plugin for WordPress is vulnerable to authorizat... |
| CVE-2026-97736 | MEDIUM | 5.4 | 0.2% | Sep 25, 2026 | tinyauth before 5.1.3 allows rule bypass by appending an allowed route string. This is caused by an unanchored regular e... |
| CVE-2026-97732 | MEDIUM | 5.1 | — | Sep 25, 2026 | IRONMACE Ironshield 1.0.0.167 has a tvk.sys kernel-mode driver that authenticates client executables by checking for exp... |
| CVE-2026-97724 | MEDIUM | 4.3 | — | Sep 25, 2026 | A prototype pollution vulnerability in Software Mansion React Native Worklets before 0.12.2 allows an attacker-controlle... |
| CVE-2026-97650 | MEDIUM | 4.3 | — | Sep 25, 2026 | A vulnerability has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. A... |
| CVE-2026-97723 | MEDIUM | 5.4 | — | Sep 25, 2026 | madpsy ka9q_ubersdr before 0.1.58 has a stored cross-site scripting (XSS) vulnerability in the chat message rendering fu... |
| CVE-2026-97649 | MEDIUM | 4.7 | 0.2% | Sep 25, 2026 | A flaw has been found in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected b... |
| CVE-2026-97648 | MEDIUM | 4.3 | 0.2% | Sep 25, 2026 | A vulnerability was detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Aff... |
| CVE-2026-97647 | MEDIUM | 5.3 | — | Sep 25, 2026 | A security vulnerability has been detected in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207c... |
| CVE-2026-95811 | MEDIUM | 6.5 | 0.4% | Sep 25, 2026 | Lemonldap::NG::Handler versions from 2.0.0 before 2.16.10, from 2.17.0 before 2.21.6, from 2.22.0 before 2.23.4 for Perl... |
| CVE-2026-85417 | MEDIUM | 6.4 | 0.2% | Sep 25, 2026 | Incomplete property masking in the SANnav logging subsystem permits SNMP authentication and privacy passwords to be reco... |
| CVE-2026-53493 | MEDIUM | 6.9 | — | Sep 25, 2026 | containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI... |
| CVE-2026-84283 | MEDIUM | 6.8 | 0.1% | Sep 25, 2026 | Secure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-stor... |
| CVE-2026-97636 | MEDIUM | 6.5 | 0.2% | Sep 24, 2026 | Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with a user-co... |
| CVE-2026-97368 | MEDIUM | 6.3 | — | Sep 24, 2026 | A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. This affects the function UserServiceImpl.userInf... |
| CVE-2026-97366 | MEDIUM | 6.3 | 1.2% | Sep 24, 2026 | A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function... |
| CVE-2026-93353 | MEDIUM | 5.3 | 0.3% | Sep 24, 2026 | copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users ... |
| CVE-2026-88386 | MEDIUM | 5.5 | 0.1% | Sep 24, 2026 | libsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_readf() while parsing WAV fmt chunks. A spec... |
| CVE-2026-87118 | MEDIUM | 5.7 | 0.2% | Sep 24, 2026 | The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functiona... |
| CVE-2026-84403 | MEDIUM | 6.2 | 0.1% | Sep 24, 2026 | The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access... |
| CVE-2026-82716 | MEDIUM | 4.6 | 0.2% | Sep 24, 2026 | The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diag... |
| CVE-2026-82708 | MEDIUM | 6.5 | 0.2% | Sep 24, 2026 | The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with acce... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now