2026 CVE Vulnerabilities
67,222 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-95814 | HIGH | 8.1 | 0.4% | Sep 22, 2026 | Vaultwarden through 1.37.3 omits organization membership status validation from three cipher access-restriction queries,... |
| CVE-2026-95813 | MEDIUM | 6.1 | 0.3% | Sep 22, 2026 | e621ng versions before 26.09.16 pass untrusted request parameters directly to Rails url_for in PaginatorComponent and co... |
| CVE-2026-95812 | MEDIUM | 6.1 | 0.4% | Sep 22, 2026 | ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site scripting vulnerability in the sort_link() helper functi... |
| CVE-2026-94450 | HIGH | 7.5 | 1.9% | Sep 22, 2026 | Improper validation of the Destination Connection ID length in s2n-quic 1.88.0 and earlier may allow an unauthenticated ... |
| CVE-2026-91018 | HIGH | 8.8 | 0.4% | Sep 22, 2026 | lwIP (Lightweight IP) has a double free vulnerability, which could crash the system, cause a DoS, memory corruption, or ... |
| CVE-2026-89019 | — | — | — | Sep 22, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-88020 | MEDIUM | 6.1 | 0.3% | Sep 22, 2026 | Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability ... |
| CVE-2026-77987 | CRITICAL | 9.8 | 0.9% | Sep 22, 2026 | A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. Th... |
| CVE-2026-77912 | MEDIUM | 5.4 | 0.4% | Sep 22, 2026 | A stored cross-site scripting (XSS) vulnerability was identified in GitHub Enterprise Server that allowed an authenticat... |
| CVE-2026-77426 | HIGH | 7.1 | 0.5% | Sep 22, 2026 | Unleash is an open-source feature management platform. Prior to 8.0.3, the Unleash admin API contains five authorization... |
| CVE-2026-77425 | MEDIUM | 4.3 | 0.3% | Sep 22, 2026 | Unleash is an open-source feature management platform. Prior to 8.0.3, POST /api/admin/projects/:projectId/features/:fea... |
| CVE-2026-76910 | MEDIUM | 5.3 | 0.4% | Sep 22, 2026 | Unleash is an open-source feature management platform. Prior to 8.0.3, cloneFeatureToggle and POST /api/admin/projects/:... |
| CVE-2026-76909 | LOW | 2.1 | 0.5% | Sep 22, 2026 | Unleash is an open-source feature management platform. Prior to 8.0.3, the change-request approval email template at src... |
| CVE-2026-75101 | MEDIUM | 6.5 | 0.4% | Sep 22, 2026 | An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of ... |
| CVE-2026-67615 | HIGH | 8.8 | 1.0% | Sep 22, 2026 | openEQUELLA before 2026.1.0 contains an authenticated remote code execution vulnerability that allows any authenticated ... |
| CVE-2026-62364 | LOW | 2.3 | 0.1% | Sep 22, 2026 | wlc is a Weblate command-line client using Weblate's REST API. Prior to 2.0.1, automatically discovered configuration fr... |
| CVE-2026-94574 | HIGH | 7.8 | 0.2% | Sep 22, 2026 | A local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a har... |
| CVE-2026-89282 | CRITICAL | 9.1 | 0.2% | Sep 22, 2026 | The Apache Lounge Windows distribution of Apache HTTP Server build contains an insecure installation directory permissio... |
| CVE-2026-89281 | HIGH | 8.4 | 0.2% | Sep 22, 2026 | The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability... |
| CVE-2026-88624 | CRITICAL | 9.1 | 0.3% | Sep 22, 2026 | Missing path validation in the Worktree.remove component of openCode v1.18.26 allows attackers to execute arbitrary recu... |
| CVE-2026-88419 | HIGH | 8.8 | 0.5% | Sep 22, 2026 | An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m=member&f=article&v=... |
| CVE-2026-88418 | HIGH | 8.8 | 0.3% | Sep 22, 2026 | CMSimple 5.24 ships with CSRF protection disabled by default, which turns csrfProtection() into a no-op on every state-c... |
| CVE-2026-88416 | — | — | 0.2% | Sep 22, 2026 | MCMS 6.1.1 through 6.2.1 has a SQL injection vulnerability in the custom model/form import feature. |
| CVE-2026-88350 | MEDIUM | 6.2 | 0.2% | Sep 22, 2026 | An integer overflow vulnerability exists in MPack 1.1.1 in mpack_node_cstr_alloc() and mpack_node_utf8_cstr_alloc(). |
| CVE-2026-88345 | HIGH | 7.5 | 0.4% | Sep 22, 2026 | An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers sche... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now