2026 CVE Vulnerabilities
65,007 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85084 | MEDIUM | 6.3 | 0.1% | Sep 3, 2026 | Out-of-bounds Write and Improper Validation of Array Index vulnerability in Samsung Open Source TizenFX Samsung/TizenFX ... |
| CVE-2026-85040 | MEDIUM | 4.7 | 1.6% | Sep 3, 2026 | A weakness has been identified in ZhongBangKeJi CRMEB up to 6.0.0. Affected by this vulnerability is the function eval o... |
| CVE-2026-85021 | MEDIUM | 4.3 | 0.4% | Sep 3, 2026 | A vulnerability was determined in langgenius dify 1.13.0. Affected is the function router.replace of the file web/app/(s... |
| CVE-2026-82918 | MEDIUM | 5.5 | 0.2% | Sep 3, 2026 | XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation improperly restrict XML external entity refere... |
| CVE-2026-78000 | MEDIUM | 5.3 | — | Sep 3, 2026 | Joomla Extension - j2commerce.com - Reflected XSS via `filter_tag`, `pricefrom` and `priceto` in J2Store 1.0.0-3.3.21, 4... |
| CVE-2026-74769 | MEDIUM | 6.5 | 0.4% | Sep 3, 2026 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain an Incorrect Authorization vulnerability in the RES... |
| CVE-2026-74768 | MEDIUM | 4.1 | 0.3% | Sep 3, 2026 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Server-Side Request Forgery (SSRF) vulnerability ... |
| CVE-2026-71224 | MEDIUM | 4.7 | 0.1% | Sep 3, 2026 | A stack overflow vulnerability was found in gfs2-utils. The metadata walk code in metawalk.c uses alloca() with an untru... |
| CVE-2026-71222 | MEDIUM | 6.3 | 0.1% | Sep 3, 2026 | A heap out-of-bounds read vulnerability was found in gfs2-utils. The ea_num_ptrs field from on-disk extended attribute m... |
| CVE-2026-71219 | MEDIUM | 4.7 | 0.1% | Sep 3, 2026 | A stack overflow vulnerability was found in gfs2-utils. The hash table traversal code in metawalk.c uses alloca() with a... |
| CVE-2026-68860 | MEDIUM | 6.8 | 0.3% | Sep 3, 2026 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Reliance on Data/Memory Layout vulnerability. An ... |
| CVE-2026-3852 | MEDIUM | 6.4 | 0.3% | Sep 3, 2026 | The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `skype_url` shortcode attribute of the... |
| CVE-2026-2573 | MEDIUM | 6.4 | 0.3% | Sep 3, 2026 | The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerabl... |
| CVE-2026-17539 | MEDIUM | 5.9 | 0.4% | Sep 3, 2026 | RTU500 has a vulnerability, where high-load scenarios, such as sending GI requests at short intervals, may cause a NULL ... |
| CVE-2026-15933 | MEDIUM | 6.9 | 0.4% | Sep 3, 2026 | OptimiDoc Server (On-Premise) stores credentials for external services in cleartext. An authenticated administrator can ... |
| CVE-2026-84888 | MEDIUM | 4.3 | 0.3% | Sep 3, 2026 | A weakness has been identified in RightNow-AI OpenFang up to 0.6.9. This vulnerability affects the function shell_exec o... |
| CVE-2026-84887 | MEDIUM | 4.3 | 0.3% | Sep 3, 2026 | A vulnerability was identified in simular-ai Agent-S up to 0.3.2. Affected by this issue is some unknown functionality o... |
| CVE-2026-84886 | MEDIUM | 5.3 | 0.4% | Sep 3, 2026 | A vulnerability was determined in simular-ai Agent-S up to 0.3.2. Affected by this vulnerability is the function ImageDa... |
| CVE-2026-84885 | MEDIUM | 4.3 | 0.3% | Sep 3, 2026 | A vulnerability has been found in simular-ai Agent-S 0.3.1/0.3.2. This impacts an unknown function of the file code_agen... |
| CVE-2026-84857 | MEDIUM | 5.3 | 0.4% | Sep 2, 2026 | A flaw has been found in sigoden aichat up to 0.30.4. This affects an unknown function of the file src/serve.rs of the c... |
| CVE-2026-84856 | MEDIUM | 5.3 | 0.4% | Sep 2, 2026 | A vulnerability was detected in rowboatlabs rowboat up to 0.9.1. The impacted element is the function request.text/req.j... |
| CVE-2026-84852 | MEDIUM | 4.4 | 0.2% | Sep 2, 2026 | A security vulnerability has been detected in Reader Tools PDF Reader App 98.8 on Android. The affected element is the f... |
| CVE-2026-75137 | MEDIUM | 6.1 | 0.1% | Sep 2, 2026 | UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recov... |
| CVE-2026-75136 | MEDIUM | 6.1 | 0.1% | Sep 2, 2026 | UpSignOn for Windows before 7.19.0 contains an insecure credential storage vulnerability that allows local attackers to ... |
| CVE-2026-75135 | MEDIUM | 6.1 | 0.1% | Sep 2, 2026 | UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recov... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now