2026 CVE Vulnerabilities
65,007 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-81282 | MEDIUM | 6.5 | — | Sep 3, 2026 | Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions. |
| CVE-2026-81281 | MEDIUM | 6.5 | 0.2% | Sep 3, 2026 | Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions. |
| CVE-2026-75602 | MEDIUM | 6.5 | 0.4% | Sep 3, 2026 | OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST... |
| CVE-2026-85239 | MEDIUM | 6.5 | 0.2% | Sep 3, 2026 | A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify even... |
| CVE-2026-85238 | MEDIUM | 6.8 | 0.2% | Sep 3, 2026 | MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a us... |
| CVE-2026-84967 | MEDIUM | 4.3 | 0.2% | Sep 3, 2026 | A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection strin... |
| CVE-2026-84966 | MEDIUM | 5.5 | 0.1% | Sep 3, 2026 | An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a lengt... |
| CVE-2026-84965 | MEDIUM | 5.5 | 0.1% | Sep 3, 2026 | An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be... |
| CVE-2026-84963 | MEDIUM | 5.3 | 0.2% | Sep 3, 2026 | An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusua... |
| CVE-2026-84962 | MEDIUM | 4.2 | 0.1% | Sep 3, 2026 | An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google ... |
| CVE-2026-82525 | MEDIUM | 5.5 | 0.1% | Sep 3, 2026 | Exterro FTK Imager before 8.3 contains an XML external entity (XXE) injection vulnerability that allows attackers to rea... |
| CVE-2026-75036 | MEDIUM | 5.3 | 0.2% | Sep 3, 2026 | A security vulnerability was discovered in Fleet's Helm template preprocessing where templates evaluated by the Fleet co... |
| CVE-2026-75035 | MEDIUM | 6.5 | 0.2% | Sep 3, 2026 | A flaw was found in Rancher Manager. When a non-administrative caller supplied a label selector naming a different user,... |
| CVE-2026-53720 | MEDIUM | 5.1 | 0.1% | Sep 3, 2026 | pymonocypher uses cython to wrap the Monocypher C library. Prior to version 4.0.2.8, the argon2i_32 implementation does ... |
| CVE-2026-50554 | MEDIUM | 5.3 | 0.2% | Sep 3, 2026 | Note Mark is an open-source note-taking application. Prior to version 0.19.5, GET /api/books/{bookID}/notes is an unauth... |
| CVE-2026-85230 | MEDIUM | 5.4 | 0.3% | Sep 3, 2026 | A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget configuration. Dashboard widge... |
| CVE-2026-85227 | MEDIUM | 6.1 | 0.3% | Sep 3, 2026 | MISP contains a reflected Cross-Site Scripting (XSS) vulnerability in the event attribute filtering query builder. The t... |
| CVE-2026-85226 | MEDIUM | 4.3 | 0.2% | Sep 3, 2026 | MISP contains an authorization flaw in the OnDemand correlation engine where correlations were calculated solely from ma... |
| CVE-2026-85210 | MEDIUM | 4.3 | 0.2% | Sep 3, 2026 | Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registere... |
| CVE-2026-85177 | MEDIUM | 5.4 | 0.2% | Sep 3, 2026 | CRMEB through 6.0.0 fails to validate message ownership in the edit_message handler of MessageSystemController.php, allo... |
| CVE-2026-85135 | MEDIUM | 6.3 | — | Sep 3, 2026 | A security flaw has been discovered in ILIAS up to 9.21/10.9/11.2. This affects the function ilObjMediaObjectGUI::upload... |
| CVE-2026-84971 | MEDIUM | 6.5 | 0.2% | Sep 3, 2026 | Improper handling of an unexpected value size in the decryption path of a client-side encryption library can cause a fai... |
| CVE-2026-84970 | MEDIUM | 5.8 | 0.1% | Sep 3, 2026 | A numeric truncation weakness exists in the JSON parsing component of the MongoDB C++ Driver's BSON library. An actor wh... |
| CVE-2026-71403 | MEDIUM | 6.1 | 0.2% | Sep 3, 2026 | A flaw was found in Rancher Manager. The /v3/users update path did not enforce immutability of a User resource's `userna... |
| CVE-2026-63694 | MEDIUM | 5 | — | Sep 3, 2026 | Dell SmartFabric OS10 Software, versions prior to 10.5.6.14, contains an Improper Neutralization of Special Elements use... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now