2026 CVE Vulnerabilities
64,952 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-81802 | MEDIUM | 6.5 | — | Sep 8, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in WpEvently <= 5.6.0 versions. |
| CVE-2026-81792 | MEDIUM | 6.5 | 0.3% | Sep 8, 2026 | Incorrect Privilege Assignment vulnerability in MultiVendorX Product Catalog Enquiry for WooCommerce by MultiVendorX woo... |
| CVE-2026-86519 | MEDIUM | 5.3 | 0.3% | Sep 8, 2026 | A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /car... |
| CVE-2026-86518 | MEDIUM | 6.3 | — | Sep 8, 2026 | A vulnerability has been found in code-projects Student Crud Operation 1.0. This affects an unknown function of the file... |
| CVE-2026-86517 | MEDIUM | 6.3 | 0.2% | Sep 8, 2026 | A flaw has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is the function mysqli_query ... |
| CVE-2026-86516 | MEDIUM | 4.7 | 0.2% | Sep 8, 2026 | A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown fun... |
| CVE-2026-86515 | MEDIUM | 4.3 | 0.3% | Sep 8, 2026 | A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/... |
| CVE-2026-86514 | MEDIUM | 6.3 | 0.3% | Sep 8, 2026 | A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txt... |
| CVE-2026-86513 | MEDIUM | 5.3 | — | Sep 8, 2026 | A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function Tr... |
| CVE-2026-86512 | MEDIUM | 6.3 | 0.2% | Sep 8, 2026 | A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/M... |
| CVE-2026-86511 | MEDIUM | 5.3 | — | Sep 8, 2026 | A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this vulnerability is the function BigDe... |
| CVE-2026-75811 | MEDIUM | 5.8 | 0.1% | Sep 8, 2026 | Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify har... |
| CVE-2026-75810 | MEDIUM | 5.7 | 0.1% | Sep 8, 2026 | Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing... |
| CVE-2026-75809 | MEDIUM | 5.9 | 0.1% | Sep 8, 2026 | Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and d... |
| CVE-2026-75808 | MEDIUM | 5.7 | 0.1% | Sep 8, 2026 | Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-serv... |
| CVE-2026-18023 | MEDIUM | 5.7 | 0.1% | Sep 8, 2026 | Sensitive Information in Resource Not Removed Before Reuse in ASUS Armoury Crate driver allows a local user to disclose ... |
| CVE-2026-16006 | MEDIUM | 5.7 | 0.1% | Sep 8, 2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user t... |
| CVE-2026-16005 | MEDIUM | 5.8 | 0.1% | Sep 8, 2026 | Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a craft... |
| CVE-2026-16004 | MEDIUM | 5.9 | 0.1% | Sep 8, 2026 | Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary P... |
| CVE-2026-12962 | MEDIUM | 5.3 | 0.4% | Sep 8, 2026 | A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local... |
| CVE-2026-76977 | MEDIUM | 4.3 | 0.2% | Sep 8, 2026 | SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated at... |
| CVE-2026-76971 | MEDIUM | 6.5 | 0.1% | Sep 8, 2026 | Due to a Server-Side Request Forgery (SSRF) vulnerability in SAP Manufacturing Integration and Intelligence, an attacker... |
| CVE-2026-76968 | MEDIUM | 6.5 | 0.2% | Sep 8, 2026 | SAP Web Dispatcher, Internet Communication Manager and SAP Content Server allows an authenticated low-privileged attacke... |
| CVE-2026-76963 | MEDIUM | 4.3 | 0.2% | Sep 8, 2026 | Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated att... |
| CVE-2026-76962 | MEDIUM | 4.3 | 0.2% | Sep 8, 2026 | SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functional... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now