2026 CVE Vulnerabilities
64,952 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-73321 | MEDIUM | 6.5 | 0.4% | Sep 8, 2026 | XenForo before 2.3.13 contains an uncontrolled recursion vulnerability in the BBCode parser that allows authenticated at... |
| CVE-2026-73320 | MEDIUM | 6.1 | 0.3% | Sep 8, 2026 | XenForo before 2.3.13 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attac... |
| CVE-2026-73319 | MEDIUM | 6.1 | 0.3% | Sep 8, 2026 | XenForo before 2.3.13 contains a cross-site scripting vulnerability in the dynamic redirect handler that allows unauthen... |
| CVE-2026-73310 | MEDIUM | 5.9 | 0.4% | Sep 8, 2026 | XenForo before 2.3.13 contains an authorization flaw in the OAuth2 token endpoint that allows attackers controlling any ... |
| CVE-2026-33391 | MEDIUM | 5.4 | — | Sep 8, 2026 | An access control vulnerability was discovered in the Smart Polling configuration functionality due to insufficient vali... |
| CVE-2026-33387 | MEDIUM | 4.6 | — | Sep 8, 2026 | A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input... |
| CVE-2026-79603 | MEDIUM | 4.3 | — | Sep 8, 2026 | x86 PV guests can free memory pages while still keeping a stale TLB entry pointing to them. A TLB flush is only issued ... |
| CVE-2026-62437 | MEDIUM | 6.5 | 0.2% | Sep 8, 2026 | When guests are terminated, various pieces of cleanup need carrying out. The cleaning up of PCI devices which were assig... |
| CVE-2026-86714 | MEDIUM | 5.4 | 0.2% | Sep 8, 2026 | PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to ... |
| CVE-2026-76931 | MEDIUM | 6.4 | — | Sep 8, 2026 | The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘message’ parameter... |
| CVE-2026-2520 | MEDIUM | 5.4 | — | Sep 8, 2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to unauthorized modific... |
| CVE-2026-18021 | MEDIUM | 6.5 | — | Sep 8, 2026 | The The Beaver Builder Page Builder – Drag and Drop Website Builder plugin for WordPress is vulnerable to arbitrary shor... |
| CVE-2026-17509 | MEDIUM | 6.5 | — | Sep 8, 2026 | The WPML Multilingual CMS plugin for WordPress is vulnerable to time-based SQL Injection via the ‘elementIds’ parameter ... |
| CVE-2026-12230 | MEDIUM | 6.4 | 0.2% | Sep 8, 2026 | The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Stored Cr... |
| CVE-2026-77654 | MEDIUM | 6.1 | — | Sep 8, 2026 | Improper Privilege Management vulnerability in Horizon Security Analyzer (formerly AlgoSec Firewall Analyzer) on Linux, ... |
| CVE-2026-19614 | MEDIUM | 5.3 | 0.2% | Sep 8, 2026 | The API is prone to XML external entity (XXE) injection. By default, XML external entity support is enabled. This issue ... |
| CVE-2026-86590 | MEDIUM | 6.3 | — | Sep 8, 2026 | In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passe... |
| CVE-2026-77132 | MEDIUM | 5.3 | 0.4% | Sep 8, 2026 | It has been discovered that several AJAX routes used for the backend localization wizard failed to perform authorization... |
| CVE-2026-86597 | MEDIUM | 6.5 | 0.1% | Sep 8, 2026 | Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers ... |
| CVE-2026-86550 | MEDIUM | 6.5 | 0.3% | Sep 8, 2026 | NuBrowser lacks protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to i... |
| CVE-2026-74859 | MEDIUM | 6.8 | 0.1% | Sep 8, 2026 | The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. A... |
| CVE-2026-62654 | MEDIUM | 6.8 | 0.1% | Sep 8, 2026 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A special maintenance mode can be activated... |
| CVE-2026-62653 | MEDIUM | 6.8 | 0.2% | Sep 8, 2026 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The input received over a proprietary commu... |
| CVE-2026-62652 | MEDIUM | 5.3 | 0.2% | Sep 8, 2026 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The device firmware contains binaries from ... |
| CVE-2026-58113 | MEDIUM | 6.1 | 0.2% | Sep 8, 2026 | A vulnerability has been identified in Teamcenter V2412 (All versions < V2412.0013), Teamcenter V2506 (All versions < V2... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now