2026 CVE Vulnerabilities
67,186 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86583 | HIGH | 8.8 | 0.3% | Sep 23, 2026 | The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up ... |
| CVE-2026-81537 | HIGH | 8.8 | 1.0% | Sep 23, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to... |
| CVE-2026-81536 | HIGH | 7.7 | 0.3% | Sep 23, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information ... |
| CVE-2026-81208 | HIGH | 7.7 | 0.2% | Sep 23, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to imp... |
| CVE-2026-80423 | HIGH | 8.8 | 0.3% | Sep 23, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information ... |
| CVE-2026-75887 | HIGH | 7.5 | 0.4% | Sep 23, 2026 | A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by man... |
| CVE-2026-57854 | — | — | — | Sep 23, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-19125 | HIGH | 8.1 | 0.6% | Sep 23, 2026 | The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includi... |
| CVE-2026-96556 | HIGH | 7.3 | 0.3% | Sep 23, 2026 | A flaw has been found in Neethuharii CafeManagement. Affected by this vulnerability is the function addcashier of the fi... |
| CVE-2026-82369 | HIGH | 8.6 | 0.5% | Sep 23, 2026 | Insufficient input sanitization of shell metacharacters in the Brocade SANnav CLI scripting component permits authentica... |
| CVE-2026-80425 | HIGH | 8.8 | 0.9% | Sep 23, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du... |
| CVE-2026-80412 | HIGH | 8.8 | 0.5% | Sep 23, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to... |
| CVE-2026-80379 | HIGH | 8.8 | 0.9% | Sep 23, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du... |
| CVE-2026-75886 | HIGH | 7.2 | 0.3% | Sep 23, 2026 | A flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the Catalogd... |
| CVE-2026-6935 | HIGH | 7.8 | — | Sep 23, 2026 | IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequatel... |
| CVE-2026-6928 | CRITICAL | 9.8 | — | Sep 23, 2026 | IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can i... |
| CVE-2026-6925 | MEDIUM | 5.3 | — | Sep 23, 2026 | IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to traverse directories on the system. An attacker could s... |
| CVE-2026-6794 | HIGH | 7.8 | — | Sep 23, 2026 | IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management. A local ... |
| CVE-2026-6730 | HIGH | 7.8 | — | Sep 23, 2026 | IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user cou... |
| CVE-2026-6721 | CRITICAL | 9.8 | — | Sep 23, 2026 | IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is inc... |
| CVE-2026-6718 | MEDIUM | 6.2 | — | Sep 23, 2026 | IBM Concert 1.0.0 through 3.0.0 is vulnerable to improper access control which allows unauthorized modification of appli... |
| CVE-2026-67405 | MEDIUM | 5.3 | 0.1% | Sep 23, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, Neither the W... |
| CVE-2026-67404 | CRITICAL | 9.2 | — | Sep 23, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, When no CA bu... |
| CVE-2026-67240 | LOW | 2.3 | 0.3% | Sep 23, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, pattern_to_regex maps % -> .*? and _ ->... |
| CVE-2026-67235 | HIGH | 7.1 | 0.3% | Sep 23, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 4.3.0, 4.2.6, 4.1.11, 4.0.20, and 3.13.15, The content-h... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now