2026 CVE Vulnerabilities
65,063 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-81162 | MEDIUM | 5.3 | 0.3% | Sep 2, 2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Drupal DXPR Builder: The Best Editing (AI) Experience... |
| CVE-2026-81160 | MEDIUM | 6.1 | — | Sep 2, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Slick Carou... |
| CVE-2026-81158 | MEDIUM | 5.3 | — | Sep 2, 2026 | Incorrect Authorization vulnerability in Drupal Entity API allows Forceful Browsing. This issue affects Entity API versi... |
| CVE-2026-76758 | MEDIUM | 5.9 | — | Sep 2, 2026 | Vulnerability in Drupal Link content parser. This issue affects Link content parser versions: *.*. |
| CVE-2026-76757 | MEDIUM | 5.9 | 0.2% | Sep 2, 2026 | Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*. |
| CVE-2026-76756 | MEDIUM | 5.9 | 0.2% | Sep 2, 2026 | Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*. |
| CVE-2026-76755 | MEDIUM | 5.9 | 0.2% | Sep 2, 2026 | Vulnerability in Drupal Gammu SMS Daemon. This issue affects Gammu SMS Daemon versions: *.*. |
| CVE-2026-73478 | MEDIUM | 5.3 | 0.2% | Sep 2, 2026 | Incorrect Authorization vulnerability in Drupal Diff allows Forceful Browsing. This issue affects Diff versions: from 0.... |
| CVE-2026-73477 | MEDIUM | 5.3 | 0.2% | Sep 2, 2026 | Incorrect Authorization vulnerability in Drupal Quick Tabs allows Forceful Browsing. This issue affects Quick Tabs versi... |
| CVE-2026-73476 | MEDIUM | 5.4 | 0.2% | Sep 2, 2026 | Improper Handling of Case Sensitivity vulnerability in Drupal External Authentication allows Privilege Escalation. This ... |
| CVE-2026-73474 | MEDIUM | 5.3 | 0.3% | Sep 2, 2026 | Server-Side Request Forgery (SSRF) vulnerability in Drupal Entity Share Websub allows Server Side Request Forgery. This ... |
| CVE-2026-18986 | MEDIUM | 4.8 | 0.1% | Sep 2, 2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Entity Brow... |
| CVE-2026-16647 | MEDIUM | 4.1 | 0.3% | Sep 2, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality... |
| CVE-2026-84835 | MEDIUM | 5.3 | 0.2% | Sep 2, 2026 | Missing Authorization vulnerability in DimaFreund Rentsyst rentsyst allows Exploiting Incorrectly Configured Access Cont... |
| CVE-2026-84808 | MEDIUM | 4.3 | — | Sep 2, 2026 | Kimai versions before 2.65.0 contain an authorization bypass vulnerability in the REST API timesheet collection endpoint... |
| CVE-2026-84807 | MEDIUM | 5.4 | — | Sep 2, 2026 | Kimai (kimai/kimai) through 2.65.0 contains a business logic / improper authorization vulnerability in the default team ... |
| CVE-2026-84806 | MEDIUM | 5.4 | — | Sep 2, 2026 | Kimai before 2.63.0 contains an improper authorization vulnerability in team access endpoints that allows authenticated ... |
| CVE-2026-84805 | MEDIUM | 4.3 | — | Sep 2, 2026 | Kimai versions from 2.61.0 before 2.63.0 fail to disable admin-only work-contract preferences for low-privilege users in... |
| CVE-2026-84804 | MEDIUM | 5.4 | 0.2% | Sep 2, 2026 | Kimai before 2.65.0 fails to properly validate permissions when removing team access to activities, projects, and custom... |
| CVE-2026-84802 | MEDIUM | 4.3 | — | Sep 2, 2026 | Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::action... |
| CVE-2026-84799 | MEDIUM | 4.3 | 0.2% | Sep 2, 2026 | Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, aut... |
| CVE-2026-84797 | MEDIUM | 6.3 | — | Sep 2, 2026 | Craft CMS versions before 5.10.11 contain an authorization bypass vulnerability in ElementsController::actionDuplicate()... |
| CVE-2026-84793 | MEDIUM | 4.8 | — | Sep 2, 2026 | Craft CMS versions from 5.0.0-RC1 before 5.10.11 contain a stored cross-site scripting vulnerability in the site name fi... |
| CVE-2026-84792 | MEDIUM | 4.3 | — | Sep 2, 2026 | Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements end... |
| CVE-2026-84781 | MEDIUM | 6.5 | — | Sep 2, 2026 | Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.4 versions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now