2026 CVE Vulnerabilities
64,997 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-82729 | MEDIUM | 6.3 | 0.5% | Sep 4, 2026 | Inefficient Algorithmic Complexity vulnerability in elixir-mint mint allows a remote HTTP server to exhaust CPU on the c... |
| CVE-2026-81859 | MEDIUM | 6.2 | 0.1% | Sep 4, 2026 | CP4BA - IBM Enterprise Records could allow a local attacker to obtain sensitive information due to the use of a broken o... |
| CVE-2026-19727 | MEDIUM | 6.1 | 0.1% | Sep 4, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information... |
| CVE-2026-14466 | MEDIUM | 4.3 | 0.2% | Sep 4, 2026 | It’s possible to run a stored XSS in Stormshield’s web administration panel. To exploit this vulnerability, a SNS adm... |
| CVE-2026-85522 | MEDIUM | 5.3 | 0.5% | Sep 4, 2026 | A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. Affected by this vulnerability is the function creat... |
| CVE-2026-85517 | MEDIUM | 5.3 | 0.5% | Sep 4, 2026 | A flaw has been found in code-projects Vehicle Management System 1.0. The impacted element is an unknown function of the... |
| CVE-2026-77818 | MEDIUM | 6.1 | 0.2% | Sep 4, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information... |
| CVE-2026-19081 | MEDIUM | 4.3 | 0.2% | Sep 4, 2026 | Missing Authorization vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Accessing Functionality ... |
| CVE-2026-19057 | MEDIUM | 5.4 | 0.1% | Sep 4, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gastromenum Gastro... |
| CVE-2026-85514 | MEDIUM | 6.3 | — | Sep 4, 2026 | A security vulnerability has been detected in StackStorm st2 up to 3.9.0. Impacted is an unknown function of the file st... |
| CVE-2026-85513 | MEDIUM | 6.3 | 0.2% | Sep 4, 2026 | A weakness has been identified in StackStorm st2 up to 3.9.0. This issue affects the function assert_user_is_admin_if_us... |
| CVE-2026-82309 | MEDIUM | 4.3 | 0.2% | Sep 4, 2026 | Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded outbound DNS queries per validation via a fo... |
| CVE-2026-74237 | MEDIUM | 6.5 | 0.2% | Sep 4, 2026 | GFI Exinda AI and ClearView before 7.6.5 contains an argument injection vulnerability in the Tools Iperf Client function... |
| CVE-2026-74236 | MEDIUM | 6.5 | 0.6% | Sep 4, 2026 | GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the diagnostic file deletion handler... |
| CVE-2026-74235 | MEDIUM | 4.9 | 0.6% | Sep 4, 2026 | GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the system maintenance configuration... |
| CVE-2026-85615 | MEDIUM | 6.4 | 0.1% | Sep 4, 2026 | Openpanel before 2.3.0 contains an insecure direct object reference vulnerability in the report.getLayouts and report.re... |
| CVE-2026-85611 | MEDIUM | 6.4 | 0.2% | Sep 4, 2026 | OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in the report.getLayouts ... |
| CVE-2026-85603 | MEDIUM | 6.5 | 0.4% | Sep 4, 2026 | Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to v... |
| CVE-2026-85602 | MEDIUM | 5.3 | 0.3% | Sep 4, 2026 | The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate b... |
| CVE-2026-85601 | MEDIUM | 5.4 | 0.2% | Sep 4, 2026 | Grav Admin before 2.0.20 fails to sanitize output from marked.parse() before injecting it into the DOM via Svelte's {@ht... |
| CVE-2026-85600 | MEDIUM | 5.4 | 0.2% | Sep 4, 2026 | Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a stored cross-site scripting vulnerability in the tH... |
| CVE-2026-85598 | MEDIUM | 6.4 | 0.2% | Sep 4, 2026 | Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page e... |
| CVE-2026-85593 | MEDIUM | 5.4 | 0.1% | Sep 4, 2026 | phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting vulnerability in FaqHelper::convertOldInternalLinks... |
| CVE-2026-85589 | MEDIUM | 5.3 | 0.3% | Sep 4, 2026 | phpMyFAQ before 4.2.0-alpha.2 contains a missing authorization vulnerability in the admin dashboard API endpoints search... |
| CVE-2026-85588 | MEDIUM | 5.3 | 0.4% | Sep 4, 2026 | phpMyFAQ versions before 4.1.8 include live TOTP shared secrets in plaintext within user data export ZIP files. Attacker... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now