2026 CVE Vulnerabilities
64,755 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86424 | LOW | 2.5 | 0.1% | Sep 7, 2026 | ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-time-of-use (TOCTOU) vulnerability in the video decod... |
| CVE-2026-86422 | LOW | 3.3 | 0.1% | Sep 7, 2026 | ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use vulnerability in path policy enforcement on Windows tha... |
| CVE-2026-86301 | LOW | 3.5 | 0.2% | Sep 7, 2026 | A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the ... |
| CVE-2026-82312 | LOW | 1.8 | 0.1% | Sep 7, 2026 | OpenVPN 2.0.0 through 2.6.22 and 2.7_alpha1 through 2.7.6 on Windows allows local authenticated users to cause a denial ... |
| CVE-2026-81738 | LOW | 2.3 | 0.3% | Sep 7, 2026 | OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 driver allows attackers to trigger an out-of-bounds write ... |
| CVE-2026-86231 | LOW | 3.7 | 0.3% | Sep 6, 2026 | A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src... |
| CVE-2026-86227 | LOW | 3.1 | 0.3% | Sep 6, 2026 | A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of t... |
| CVE-2026-86226 | LOW | 3.5 | 0.2% | Sep 6, 2026 | A security flaw has been discovered in Projectwolds Online Attendance System 1.0. Affected by this issue is some unknown... |
| CVE-2026-86181 | LOW | 3.5 | 0.2% | Sep 6, 2026 | A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functional... |
| CVE-2026-84927 | LOW | 2.7 | 0.2% | Sep 5, 2026 | The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Rev... |
| CVE-2026-84926 | LOW | 2.7 | 0.2% | Sep 5, 2026 | The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST route... |
| CVE-2026-84745 | LOW | 2.7 | 0.2% | Sep 5, 2026 | The Events Calendar WordPress plugin before 6.17.3.1 does not restrict non-public content to the users entitled to read ... |
| CVE-2026-84225 | LOW | 2.2 | 0.1% | Sep 5, 2026 | The Kirki WordPress plugin before 6.3.0 does not check that a user is allowed to act on a collaboration comment before ... |
| CVE-2026-81348 | LOW | 3.7 | 0.2% | Sep 5, 2026 | The My Private Site WordPress plugin before 4.2.3 does not apply its site-privacy access control to certain unauthentic... |
| CVE-2026-78150 | LOW | 2.7 | 0.2% | Sep 5, 2026 | The Smart Post WordPress plugin before 4.0.8 does not check the type, ownership or status of the post it is asked to du... |
| CVE-2026-86141 | LOW | 3.3 | 0.1% | Sep 5, 2026 | xmlregexp in libxml2 before 2.15.4 has a NULL pointer dereference in xmlRegNewParserCtxt after a strdup failure, i.e., i... |
| CVE-2026-85704 | LOW | 3.7 | 0.3% | Sep 4, 2026 | A security flaw has been discovered in ramon-victor freegpt-webui up to 098db3dfeb41555c2ca9269df0f13e10ec1c35dc. This i... |
| CVE-2026-18540 | LOW | 3.7 | 0.2% | Sep 4, 2026 | undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier par... |
| CVE-2026-17483 | LOW | 3.3 | 0.1% | Sep 4, 2026 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 IBM i could allow a local attacker to delete historical flight-recorder archives ... |
| CVE-2026-85592 | LOW | 3.7 | 0.2% | Sep 4, 2026 | phpMyFAQ before 4.1.8 contains an authorization bypass vulnerability in the question creation endpoint where the isAddin... |
| CVE-2026-84066 | LOW | 3.1 | 0.1% | Sep 4, 2026 | The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9 does not verify th... |
| CVE-2026-85406 | LOW | 3.5 | 0.2% | Sep 4, 2026 | A vulnerability has been found in Eleveo Quality Management 9.7.0. This vulnerability affects unknown code of the compon... |
| CVE-2026-85405 | LOW | 3.5 | 0.2% | Sep 4, 2026 | A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callrec/roleAdd... |
| CVE-2026-45197 | LOW | 2.5 | 0.1% | Sep 4, 2026 | Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a read... |
| CVE-2026-85458 | LOW | 2.1 | 0.1% | Sep 3, 2026 | Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a Type 3 font has a zero height. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now