2026 CVE Vulnerabilities
64,755 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-77703 | MEDIUM | 5.9 | — | Sep 24, 2026 | Key exchange without entity authentication vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Mi... |
| CVE-2026-6544 | MEDIUM | 6.2 | — | Sep 24, 2026 | IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to uninte... |
| CVE-2026-65422 | MEDIUM | 6.5 | — | Sep 24, 2026 | A flaw in the authorization mechanism for Media Gateway API in Genetec Security Center may allow a user with no playback... |
| CVE-2026-18870 | MEDIUM | 4.3 | — | Sep 24, 2026 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.... |
| CVE-2026-97062 | MEDIUM | 5.4 | — | Sep 24, 2026 | Aureus ERP through 1.6.0 stores uploaded SVG files on its public disk and serves them from the application origin, allow... |
| CVE-2026-97061 | MEDIUM | 4.3 | — | Sep 24, 2026 | Black Candy through 3.2.1 fails to scope playlist search queries to the authenticated session user, allowing any authent... |
| CVE-2026-97058 | MEDIUM | 5.3 | — | Sep 24, 2026 | sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods withou... |
| CVE-2026-88359 | MEDIUM | 6.5 | 0.2% | Sep 24, 2026 | libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format(). When processing a specially crafted Y... |
| CVE-2026-77798 | MEDIUM | 6.5 | — | Sep 24, 2026 | Velociraptor contains a deadlock condition that may be triggered by authenticated users. The issue stems from a lock man... |
| CVE-2026-17504 | MEDIUM | 5.1 | — | Sep 24, 2026 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.... |
| CVE-2026-17503 | MEDIUM | 5.1 | — | Sep 24, 2026 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.... |
| CVE-2026-17413 | MEDIUM | 5.1 | — | Sep 24, 2026 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.... |
| CVE-2026-94416 | MEDIUM | 6.8 | — | Sep 24, 2026 | An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authentica... |
| CVE-2026-88916 | MEDIUM | 6.8 | — | Sep 24, 2026 | Incorrect Authorization vulnerability in TÜBİTAK ULAKBİM UlakPDF allows Privilege Escalation. This issue affects UlakPD... |
| CVE-2026-97311 | MEDIUM | 4.3 | — | Sep 24, 2026 | A flaw was found in the Admin REST API of Keycloak, an identity and access management solution. The endpoints used to re... |
| CVE-2026-4806 | MEDIUM | 6.5 | — | Sep 24, 2026 | The Custom Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized access and loss of data due... |
| CVE-2026-3253 | MEDIUM | 4.3 | — | Sep 24, 2026 | The MailerLite – Signup forms (official) plugin for WordPress is vulnerable to unauthorized modification of data due to ... |
| CVE-2026-19532 | MEDIUM | 5.3 | — | Sep 24, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in HAVELSAN Inc. Liman MYS ... |
| CVE-2026-16302 | MEDIUM | 4.3 | — | Sep 24, 2026 | The Spectra Legacy – Gutenberg Blocks plugin for WordPress is vulnerable to Sensitive Information Exposure in all versio... |
| CVE-2026-97179 | MEDIUM | 4.3 | — | Sep 24, 2026 | A security vulnerability has been detected in O2OA up to 9.5.3/10.0.2. This vulnerability affects the function list of t... |
| CVE-2026-79680 | MEDIUM | 4.5 | — | Sep 24, 2026 | Authentication bypass vulnerability in the password authentication mechanism of the Qt VNC Server module. An attacker us... |
| CVE-2026-92905 | MEDIUM | 5.3 | 2.4% | Sep 24, 2026 | ZohoCorp ManageEngine EventLog Analyzer and Log360 before build 13071 were vulnerable to a DoS vulnerability that allowe... |
| CVE-2026-4637 | MEDIUM | 5.1 | — | Sep 24, 2026 | Paessler PRTG Network Monitor before version 26.2.120.1449 is affected by a reflected Cross-Site Scripting (XSS) vulnera... |
| CVE-2026-18335 | MEDIUM | 5.4 | 0.3% | Sep 24, 2026 | The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Blind Server-Side ... |
| CVE-2026-15731 | MEDIUM | 6.4 | 0.3% | Sep 24, 2026 | The WP Multilang – Translation and Multilingual Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now