2026 CVE Vulnerabilities
64,751 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86763 | LOW | 3.5 | 0.2% | Sep 9, 2026 | Snipe-IT versions >= 7.0.12 and <= 8.6.3 contain an authorization bypass in the Livewire importer component (App\Livewir... |
| CVE-2026-86744 | LOW | 2.2 | 0.2% | Sep 9, 2026 | Snipe-IT 8.6.3 and earlier (and develop pre-release commits prior to the fix) contain a race condition in the asset chec... |
| CVE-2026-86740 | LOW | 3.8 | 0.2% | Sep 9, 2026 | Snipe-IT before 8.7.0 fails to check the return value of Storage::delete() in UploadedFilesController::destroy() and Api... |
| CVE-2026-86203 | LOW | 3.7 | 0.3% | Sep 9, 2026 | PocketMine-MP versions before 5.39.2 fail to validate entity despawn state when processing attack packets from clients. ... |
| CVE-2026-80169 | LOW | 3.3 | — | Sep 9, 2026 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ... |
| CVE-2026-79966 | LOW | 3.3 | — | Sep 9, 2026 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ... |
| CVE-2026-80239 | LOW | 2.4 | — | Sep 9, 2026 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ... |
| CVE-2026-79727 | LOW | 3.3 | — | Sep 9, 2026 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ... |
| CVE-2026-86776 | LOW | 3.3 | 0.1% | Sep 9, 2026 | KeePass versions 2.35 through 2.61.1 fail to validate KDBX header field sizes before memory allocation in the ReadHeader... |
| CVE-2026-80175 | LOW | 3.3 | 0.1% | Sep 9, 2026 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains ... |
| CVE-2026-13146 | LOW | 3.7 | 0.1% | Sep 9, 2026 | The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester owns the booking targeted by i... |
| CVE-2026-13144 | LOW | 3.7 | 0.1% | Sep 9, 2026 | The WP Travel WordPress plugin before 12.0.2 does not properly verify that the requester is authorized to modify the ta... |
| CVE-2026-21109 | LOW | 2.1 | 0.1% | Sep 9, 2026 | Improper access control in Watch Plugin prior to Android Watch 17 allows local attackers to access sensitive information... |
| CVE-2026-87657 | LOW | 3.1 | 0.2% | Sep 9, 2026 | Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer ... |
| CVE-2026-87652 | LOW | 3.1 | 0.3% | Sep 9, 2026 | Incorrect authorization in PushAPI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised... |
| CVE-2026-87647 | LOW | 3.4 | 0.2% | Sep 9, 2026 | Uninitialized resource in GPU in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the ... |
| CVE-2026-87614 | LOW | 3.1 | 0.2% | Sep 9, 2026 | Incorrect authorization in ServiceWorker in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compr... |
| CVE-2026-87611 | LOW | 3.1 | 0.2% | Sep 9, 2026 | Missing authorization in FileSystem in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromise... |
| CVE-2026-87576 | LOW | 3.4 | 0.2% | Sep 9, 2026 | Uninitialized resource in GPU in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had co... |
| CVE-2026-87539 | LOW | 3.1 | 0.2% | Sep 9, 2026 | Observable discrepancy in Network in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to obtain cross-orig... |
| CVE-2026-87531 | LOW | 3.1 | 0.2% | Sep 9, 2026 | Information leak in CORS in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the rende... |
| CVE-2026-87525 | LOW | 2.7 | 0.1% | Sep 9, 2026 | Out of bounds read in Chromoting in Google Chrome on on Windows prior to 153.0.8010.36 allowed a local attacker to read ... |
| CVE-2026-87521 | LOW | 3.1 | 0.2% | Sep 9, 2026 | Information leak in WebMCP in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the ren... |
| CVE-2026-87517 | LOW | 3.1 | 0.2% | Sep 9, 2026 | Race condition in Mobile in Google Chrome on on iOS prior to 153.0.8010.36 allowed a remote attacker leveraging social e... |
| CVE-2026-87498 | LOW | 3.1 | 0.2% | Sep 9, 2026 | Missing authorization in WebUI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now