2026 CVE Vulnerabilities
65,007 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-75134 | MEDIUM | 6.4 | 0.2% | Sep 2, 2026 | SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenti... |
| CVE-2026-84840 | MEDIUM | 6.5 | 0.5% | Sep 2, 2026 | A vulnerability was identified in tsi-coop tsi-dpdp-cms up to 0.5.0. This affects an unknown part of the file Intercepti... |
| CVE-2026-84839 | MEDIUM | 5.3 | 0.4% | Sep 2, 2026 | A vulnerability was determined in tsi-coop tsi-dpdp-cms up to 0.5.0. Affected by this issue is some unknown functionalit... |
| CVE-2026-84833 | MEDIUM | 4.3 | 0.3% | Sep 2, 2026 | A vulnerability was found in ntegrals openbrowser up to 067fc45d649baa961750da8e2f4a75d87c5c75c8. Affected by this vulne... |
| CVE-2026-84380 | MEDIUM | 5.6 | 0.2% | Sep 2, 2026 | HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, Request._prepare() in src/httpx2/httpx2/_models.py ... |
| CVE-2026-84379 | MEDIUM | 5.3 | 0.3% | Sep 2, 2026 | HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, FileField.render_headers() in src/httpx2/httpx2/_mu... |
| CVE-2026-84378 | MEDIUM | 5.9 | 0.3% | Sep 2, 2026 | HTTPX2 is a next generation HTTP client for Python. From 2.5.0 until 2.10.0, the HTTPX2 Server-Sent Events parser in src... |
| CVE-2026-84377 | MEDIUM | 6.5 | 0.3% | Sep 2, 2026 | LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to versions 1.88.6 and 1.96.... |
| CVE-2026-82522 | MEDIUM | 5.4 | 0.2% | Sep 2, 2026 | libjxl before 0.12 contains an integer underflow vulnerability in the container box parser that allows remote attackers ... |
| CVE-2026-77123 | MEDIUM | 6.5 | 0.3% | Sep 2, 2026 | Nexus Repository 3 contains a sensitive information disclosure vulnerability in the capability read API. An account hold... |
| CVE-2026-77122 | MEDIUM | 4.3 | 0.2% | Sep 2, 2026 | An authorization flaw in the REST API repository details endpoint (GET /service/rest/v1/repositories/{repositoryName}) i... |
| CVE-2026-77121 | MEDIUM | 5.3 | 0.2% | Sep 2, 2026 | A user account with permission to deploy artifacts to a hosted Maven repository could upload a POM file containing an ov... |
| CVE-2026-55221 | MEDIUM | 6.5 | 0.3% | Sep 2, 2026 | Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized iden... |
| CVE-2026-49833 | MEDIUM | 5.5 | 0.3% | Sep 2, 2026 | DSpace open source software is a repository application which provides durable access to digital resources. From version... |
| CVE-2026-49831 | MEDIUM | 5.5 | 0.3% | Sep 2, 2026 | DSpace open source software is a repository application which provides durable access to digital resources. Prior to ver... |
| CVE-2026-49830 | MEDIUM | 4.4 | 0.4% | Sep 2, 2026 | DSpace open source software is a repository application which provides durable access to digital resources. Prior to ver... |
| CVE-2026-84811 | MEDIUM | 6.5 | 0.3% | Sep 2, 2026 | agentverus-scanner fails to analyze compiled Python bytecode files in companion code directories, allowing attackers to ... |
| CVE-2026-84810 | MEDIUM | 6.5 | 0.3% | Sep 2, 2026 | claude-skill-antivirus fails to analyze executable files when scanning local skill directories, reading only SKILL.md wh... |
| CVE-2026-84809 | MEDIUM | 6.5 | 0.6% | Sep 2, 2026 | Tencent AI-Infra-Guard's skill-scan component excludes compiled Python bytecode files from analysis by hardcoding __pyca... |
| CVE-2026-84376 | MEDIUM | 6.3 | 0.4% | Sep 2, 2026 | Astro is a web framework for content-driven websites. Prior to 7.2.4, Astro stripped a configured non-root base path fro... |
| CVE-2026-55421 | MEDIUM | 6.8 | 0.3% | Sep 2, 2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 00b7c3c, the endpo... |
| CVE-2026-53636 | MEDIUM | 4.7 | 0.2% | Sep 2, 2026 | Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 3a5ac85, a securit... |
| CVE-2026-52832 | MEDIUM | 4.9 | 0.5% | Sep 2, 2026 | Nuclio is a "Serverless" framework for Real-Time Events and Data Processing. Prior to version 1.16.5, Nuclio Dashboard e... |
| CVE-2026-20355 | MEDIUM | 5.9 | — | Sep 2, 2026 | Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco ... |
| CVE-2026-20354 | MEDIUM | 5.9 | — | Sep 2, 2026 | Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now