2026 CVE Vulnerabilities
64,751 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-83591 | HIGH | 7.2 | — | Sep 25, 2026 | The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment ... |
| CVE-2026-62062 | HIGH | 8.8 | — | Sep 25, 2026 | Cross-Site Request Forgery (CSRF) vulnerability in Elementor Website Builder allows Cross Site Request Forgery. This is... |
| CVE-2026-97818 | HIGH | 8.6 | — | Sep 25, 2026 | phpIPAM through 1.8.3 has incorrect authorization for id=="admins" and id=="all" in api/controllers/User.php. |
| CVE-2026-97737 | HIGH | 7.4 | 0.3% | Sep 25, 2026 | In Wakapi before 2.17.6, the user caching service allows a lookup to be resolved in an unintended lookup context, leadin... |
| CVE-2026-97735 | HIGH | 8 | — | Sep 25, 2026 | ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages ... |
| CVE-2026-97731 | HIGH | 7.1 | 0.2% | Sep 25, 2026 | MinIO through 7aac2a2 does not verify that every x-amz-* header present on a request also appears in the client-supplied... |
| CVE-2026-97730 | HIGH | 8.5 | 1.0% | Sep 25, 2026 | In Netgate pfSense Plus before 26.07 and pfSense CE before 2.9.0, a Local File Inclusion (LFI) vulnerability in the Dash... |
| CVE-2026-97646 | HIGH | 7.3 | 0.3% | Sep 25, 2026 | A weakness has been identified in ningzichun student-management-system up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. T... |
| CVE-2026-85082 | HIGH | 8.5 | 0.1% | Sep 25, 2026 | Root Browser Classic 3.3.0 passes the path of a selected SQLite database to an operating-system shell without safely sep... |
| CVE-2026-87722 | HIGH | 8.7 | 0.3% | Sep 24, 2026 | Uncontrolled Resource Consumption (CWE-400 / CWE-1333) in regex search query predicates (such as RegexProjectPredicate, ... |
| CVE-2026-87721 | HIGH | 8.7 | 0.3% | Sep 24, 2026 | Uncontrolled Resource Consumption (CWE-400 / CWE-407) in the ANTLR 3 search query parser (QueryParser / Query.g) in Gerr... |
| CVE-2026-87720 | HIGH | 7.6 | 0.3% | Sep 24, 2026 | Incorrect Authorization (CWE-863) in project name normalization (ProjectUtil.stripGitSuffix) and ProjectCache eviction l... |
| CVE-2026-85491 | HIGH | 8.8 | 0.4% | Sep 24, 2026 | Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorizat... |
| CVE-2026-88388 | HIGH | 7.5 | 0.2% | Sep 24, 2026 | Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace ... |
| CVE-2026-81630 | HIGH | 8.1 | 0.2% | Sep 24, 2026 | The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update proce... |
| CVE-2026-14443 | HIGH | 8.4 | 0.1% | Sep 24, 2026 | Incomplete log sanitization during bulk IPsec policy collection in Brocade SANnav versions before 3.0.1a permit extensio... |
| CVE-2026-97326 | HIGH | 7.3 | 0.3% | Sep 24, 2026 | A weakness has been identified in songxinjianqwe Chat up to ac63d25297079eed5e4ba7e88d3b7a032637150d. Affected by this i... |
| CVE-2026-97324 | HIGH | 7.3 | — | Sep 24, 2026 | A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.08. Affected is the function updateDemoO... |
| CVE-2026-96883 | HIGH | 8.8 | — | Sep 24, 2026 | pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 m... |
| CVE-2026-93354 | HIGH | 8.1 | — | Sep 24, 2026 | Taskview Community before 1.56.0 contains a missing authentication vulnerability that allows unauthenticated attackers t... |
| CVE-2026-93289 | HIGH | 7.5 | — | Sep 24, 2026 | The affected products are vulnerable to command injection attack that could allow an unauthenticated attacker to execute... |
| CVE-2026-85496 | HIGH | 8.8 | 0.3% | Sep 24, 2026 | The Botslab G980H dash camera firmware generates session identifiers using a small sequential value space rather than a ... |
| CVE-2026-84399 | HIGH | 8.8 | — | Sep 24, 2026 | The Botslab G980H dash camera firmware contains an authorization vulnerability in its session based command functionalit... |
| CVE-2026-82566 | HIGH | 8.8 | — | Sep 24, 2026 | The Botslab G980H dash camera firmware contains a session management vulnerability in which authentication state can rem... |
| CVE-2026-82372 | HIGH | 8.5 | — | Sep 24, 2026 | Improper handling of sensitive data during IPsec policy creation and modification in Brocade SANnav versions before 3.0.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now