2026 CVE Vulnerabilities
67,214 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18490 | HIGH | 8.8 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via ... |
| CVE-2026-18185 | HIGH | 7.3 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to access sensitive informati... |
| CVE-2026-18184 | HIGH | 7.4 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive informati... |
| CVE-2026-18181 | HIGH | 8.1 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to bypass authentication and ... |
| CVE-2026-18180 | MEDIUM | 6.5 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensi... |
| CVE-2026-96611 | MEDIUM | 6.9 | 0.1% | Sep 23, 2026 | FFmpeg before 9.0 has a signed integer overflow in libavformat/mov.c. In mov_read_ispe(), uint32_t width/height values f... |
| CVE-2026-96609 | HIGH | 7.1 | 0.2% | Sep 23, 2026 | Robur Albatross 1.0.0 through 2.x before 2.7.2 does not limit use of the ring buffer, leading to an albatross-console lo... |
| CVE-2026-96600 | MEDIUM | 5.5 | 0.2% | Sep 23, 2026 | Isotope eCommerce through 2.9.10 contains a blind SQL injection vulnerability in backend callbacks that interpolate requ... |
| CVE-2026-96599 | MEDIUM | 5.9 | 0.4% | Sep 23, 2026 | Isotope eCommerce through 2.9.10 derives order identifiers from uniqid() instead of a cryptographically secure source, a... |
| CVE-2026-96276 | MEDIUM | 6.5 | 0.5% | Sep 23, 2026 | If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak ... |
| CVE-2026-96275 | HIGH | 8.8 | 0.4% | Sep 23, 2026 | A malicious or compromised Flatpak repository can write attacker-controlled content to arbitrary locations on the host f... |
| CVE-2026-92419 | MEDIUM | 5.3 | — | Sep 23, 2026 | WEBCON BPS is vulnerable to Insecure Direct Object Reference (IDOR) in the /api/vacations/{path} endpoint. The selectedP... |
| CVE-2026-92164 | MEDIUM | 6.5 | — | Sep 23, 2026 | Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.6.0, HTTPSes... |
| CVE-2026-88974 | MEDIUM | 5.4 | — | Sep 23, 2026 | WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjec... |
| CVE-2026-73858 | MEDIUM | 5.3 | — | Sep 23, 2026 | Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. From 5.0.0 through 5.10.13, submitted... |
| CVE-2026-73591 | HIGH | 7.5 | 0.3% | Sep 23, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Inclusion of Sensitive Infor... |
| CVE-2026-73589 | MEDIUM | 6.3 | 0.1% | Sep 23, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Weak ... |
| CVE-2026-73588 | HIGH | 7.4 | 0.2% | Sep 23, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains a Missing Authentication for Cr... |
| CVE-2026-73587 | MEDIUM | 6.8 | 0.1% | Sep 23, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validat... |
| CVE-2026-73586 | MEDIUM | 6.4 | 0.1% | Sep 23, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Insufficient Session Expirat... |
| CVE-2026-71178 | LOW | 3.7 | 0.2% | Sep 23, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Pat... |
| CVE-2026-71177 | MEDIUM | 5.4 | 0.1% | Sep 23, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rend... |
| CVE-2026-63002 | MEDIUM | 4.8 | 0.2% | Sep 23, 2026 | REDAXO is a PHP-based content management system. Prior to 5.21.2, redaxo/src/addons/mediapool/pages/sync.php inserts fil... |
| CVE-2026-63001 | MEDIUM | 4.8 | — | Sep 23, 2026 | REDAXO is a PHP-based content management system. Prior to 5.21.2, the mediaIsInUse() handler in redaxo/src/addons/media_... |
| CVE-2026-63000 | MEDIUM | 6.4 | — | Sep 23, 2026 | REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_api_install_package_update in redaxo/src/addons/in... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now