2026 CVE Vulnerabilities
64,982 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13159 | MEDIUM | 4.3 | 0.1% | Sep 6, 2026 | The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions... |
| CVE-2026-86170 | MEDIUM | 6.3 | 0.2% | Sep 6, 2026 | A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /mod... |
| CVE-2026-86164 | MEDIUM | 6.3 | 0.2% | Sep 6, 2026 | A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of t... |
| CVE-2026-86163 | MEDIUM | 6.3 | 0.2% | Sep 6, 2026 | A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the f... |
| CVE-2026-86150 | MEDIUM | 4.1 | 0.2% | Sep 5, 2026 | A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-... |
| CVE-2026-86206 | MEDIUM | 6.9 | 0.3% | Sep 5, 2026 | A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is... |
| CVE-2026-67279 | MEDIUM | 6.5 | 0.7% | Sep 5, 2026 | RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never att... |
| CVE-2026-6554 | MEDIUM | 5.5 | 0.1% | Sep 5, 2026 | libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement looping via bac... |
| CVE-2026-6244 | MEDIUM | 5.5 | 0.1% | Sep 5, 2026 | libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zer... |
| CVE-2026-31912 | MEDIUM | 5.5 | 0.1% | Sep 5, 2026 | libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instructio... |
| CVE-2026-31911 | MEDIUM | 5.5 | 0.1% | Sep 5, 2026 | libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular unco... |
| CVE-2026-18313 | MEDIUM | 4.3 | 0.2% | Sep 5, 2026 | rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received fro... |
| CVE-2026-18238 | MEDIUM | 5 | 0.2% | Sep 5, 2026 | The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its heade... |
| CVE-2026-82752 | MEDIUM | 5.9 | 0.1% | Sep 5, 2026 | Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to store a value ... |
| CVE-2026-86197 | MEDIUM | 5.1 | 0.3% | Sep 5, 2026 | Grav before 2.0.20 contains a cross-site scripting vulnerability in the Twig sandbox policy that allowlists addJs and ad... |
| CVE-2026-86194 | MEDIUM | 6.9 | 0.3% | Sep 5, 2026 | Grav Form Plugin before 9.1.22 fails to verify page authorization when resolving forms by name across pages, allowing an... |
| CVE-2026-86192 | MEDIUM | 6.5 | 0.2% | Sep 5, 2026 | SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys end... |
| CVE-2026-86191 | MEDIUM | 4.3 | 0.2% | Sep 5, 2026 | SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint t... |
| CVE-2026-86187 | MEDIUM | 5.9 | 0.2% | Sep 5, 2026 | WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing... |
| CVE-2026-86186 | MEDIUM | 6.5 | 0.2% | Sep 5, 2026 | AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eigh... |
| CVE-2026-15550 | MEDIUM | 4.3 | 0.2% | Sep 5, 2026 | The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and inclu... |
| CVE-2026-12843 | MEDIUM | 5.4 | 0.2% | Sep 5, 2026 | The LearnDash LMS plugin for WordPress is vulnerable to authorization bypass in versions 4.25.0 - 5.1.6. This is due to ... |
| CVE-2026-86178 | MEDIUM | 5.4 | 0.2% | Sep 5, 2026 | Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowin... |
| CVE-2026-86176 | MEDIUM | 4.3 | 0.2% | Sep 5, 2026 | NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, S... |
| CVE-2026-86175 | MEDIUM | 6.5 | 0.3% | Sep 5, 2026 | NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authen... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now