2026 CVE Vulnerabilities
64,982 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86416 | MEDIUM | 5.4 | 0.3% | Sep 7, 2026 | ILIAS versions before 9.23, 10.11, and 11.4 contain an authorization bypass vulnerability in ilObjGroupGUI where saveMap... |
| CVE-2026-86408 | MEDIUM | 6.5 | 0.2% | Sep 7, 2026 | Affected versions of MISP do not enforce parent-event visibility when serving cryptographic keys through CryptographicKe... |
| CVE-2026-86302 | MEDIUM | 5.3 | 0.3% | Sep 7, 2026 | A vulnerability was found in code-projects Hospital Information System 1.0. Affected by this vulnerability is an unknown... |
| CVE-2026-80135 | MEDIUM | 5.3 | 0.4% | Sep 7, 2026 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ... |
| CVE-2026-4945 | MEDIUM | 5.3 | — | Sep 7, 2026 | The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Insec... |
| CVE-2026-12853 | MEDIUM | 5.4 | 0.3% | Sep 7, 2026 | The Flamingo plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2. Thi... |
| CVE-2026-78325 | MEDIUM | 6.9 | 0.1% | Sep 7, 2026 | Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allow... |
| CVE-2026-2390 | MEDIUM | 6.4 | — | Sep 7, 2026 | The Powerkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Lazy Load module's image processi... |
| CVE-2026-86351 | MEDIUM | 6.1 | 0.3% | Sep 7, 2026 | Affected versions of MISP validate the user-configurable homepage by checking only whether the supplied path begins with... |
| CVE-2026-86294 | MEDIUM | 4.3 | 0.4% | Sep 7, 2026 | A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unkno... |
| CVE-2026-85640 | MEDIUM | 6.3 | 0.2% | Sep 7, 2026 | Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to Privilege Escalation Due to Outdate... |
| CVE-2026-85201 | MEDIUM | 6.8 | 0.1% | Sep 7, 2026 | In Eclipse Ankaios versions 0.1.0 through 1.0.1, the agent does not limit the length declared by a workload in a length-... |
| CVE-2026-82325 | MEDIUM | 6.8 | 0.1% | Sep 7, 2026 | A use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5.0 through 2.8.6 allows local authenticated... |
| CVE-2026-77699 | MEDIUM | 5 | 0.2% | Sep 7, 2026 | Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to l... |
| CVE-2026-77697 | MEDIUM | 6.3 | 0.2% | Sep 7, 2026 | Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation During JAR Ext... |
| CVE-2026-86347 | MEDIUM | 6.5 | 0.3% | Sep 7, 2026 | Affected versions of MISP allow any authenticated user to access TemplatesController::uploadFile() because the ACL entry... |
| CVE-2026-86293 | MEDIUM | 6.5 | — | Sep 7, 2026 | A flaw has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this vulnerability is an unknown ... |
| CVE-2026-86291 | MEDIUM | 6.3 | 0.3% | Sep 7, 2026 | A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. This impacts an unknown funct... |
| CVE-2026-77698 | MEDIUM | 5.7 | 0.2% | Sep 7, 2026 | Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to ... |
| CVE-2026-86342 | MEDIUM | 4.3 | 0.3% | Sep 7, 2026 | Affected versions of MISP contain improper authorization checks in the freetext feed preview functionality. The preview ... |
| CVE-2026-86332 | MEDIUM | 6.5 | 0.2% | Sep 7, 2026 | A flaw was found in odh-dashboard in Red Hat OpenShift AI. The backend-for-frontend route GET /api/nim-serving/:nimResou... |
| CVE-2026-86289 | MEDIUM | 4.3 | 0.4% | Sep 7, 2026 | A vulnerability was found in Ollama up to 0.31.1. This issue affects the function readGGUFV1String of the file fs/ggml/g... |
| CVE-2026-86288 | MEDIUM | 6.3 | 0.3% | Sep 7, 2026 | A vulnerability has been found in ModelCloud GPTQModel up to 7.2.0. This vulnerability affects unknown code of the file ... |
| CVE-2026-86285 | MEDIUM | 4.3 | 0.2% | Sep 7, 2026 | A vulnerability was detected in BookStack up to 26.05.2. Affected by this issue is the function AttachmentController::ge... |
| CVE-2026-84186 | MEDIUM | 6.9 | 0.3% | Sep 7, 2026 | Vulnerability involving incorrect access control in the Tools::getRemoteAddr() function in PrestaShop, which allows the ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now