2026 CVE Vulnerabilities
64,704 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100840 | HIGH | 7.8 | — | Sep 27, 2026 | MONAI through 1.6.0 contains a remote code execution vulnerability in the bundle configuration engine that resolves _tar... |
| CVE-2026-100839 | HIGH | 8.4 | — | Sep 27, 2026 | Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.18.0, the guest kernel's ACPI/AML hand... |
| CVE-2026-100838 | HIGH | 8.1 | — | Sep 27, 2026 | Contrast is a confidential-computing runtime for Kubernetes. In versions before 1.19.1, the Kata agent policies generate... |
| CVE-2026-100835 | HIGH | 7.4 | — | Sep 27, 2026 | Contrast before 1.16.0 is susceptible to remote attestation relay attacks. Contrast accepted any TEE attestation report ... |
| CVE-2026-100833 | HIGH | 8.2 | — | Sep 27, 2026 | Contrast (edgelesssys/contrast) versions 1.14.0 before 1.23.1 generate runtime policies that fail to detect all containe... |
| CVE-2026-100744 | HIGH | 7.3 | — | Sep 27, 2026 | A flaw has been found in coollabsio Coolify up to 4.1.2. The affected element is an unknown function of the file app/Htt... |
| CVE-2026-100723 | HIGH | 7.5 | — | Sep 27, 2026 | vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and buffer.byteLength ==... |
| CVE-2026-100739 | HIGH | 7.3 | — | Sep 26, 2026 | A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. ... |
| CVE-2026-72668 | HIGH | 7.3 | — | Sep 26, 2026 | Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation.... |
| CVE-2026-77203 | HIGH | 8.8 | — | Sep 26, 2026 | The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalation in all versions u... |
| CVE-2026-97162 | HIGH | 8.3 | — | Sep 26, 2026 | Joomla Extension - lomart.fr - Various SQL injection vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 |
| CVE-2026-94131 | HIGH | 8.3 | — | Sep 26, 2026 | Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0 ... |
| CVE-2026-100720 | HIGH | 8.7 | — | Sep 26, 2026 | Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authen... |
| CVE-2026-100718 | HIGH | 7.1 | — | Sep 26, 2026 | Froxlor through 2.3.10 does not enforce the mail.allow_external_domains policy in the EmailSender.add API command. When ... |
| CVE-2026-100713 | HIGH | 7.8 | — | Sep 26, 2026 | Froxlor 2.3.10 and earlier contain a time-of-check time-of-use (TOCTOU) race condition in the SSH key synchronization cr... |
| CVE-2026-100711 | HIGH | 7.5 | — | Sep 26, 2026 | froxlor versions before 2.3.12 fail to invalidate existing panel sessions, API keys, and 2FA trust cookies when a user p... |
| CVE-2026-100709 | HIGH | 7.5 | — | Sep 26, 2026 | Froxlor through 2.3.10 stores only a numeric user ID in remembered-2FA tokens (panel_2fa_tokens) without recording the a... |
| CVE-2026-100708 | HIGH | 7.1 | — | Sep 26, 2026 | Froxlor before 2.3.13 returns the ssl_key_file column — which stores the raw PEM TLS private-key content — verbatim in t... |
| CVE-2026-100707 | HIGH | 7.7 | — | Sep 26, 2026 | Kyverno before 1.19.1 contains a namespace isolation bypass in the apiCall context entry of namespaced Policy resources ... |
| CVE-2026-100705 | HIGH | 7.6 | — | Sep 26, 2026 | Kyverno before 1.19.1 is vulnerable to server-side request forgery. The default egress blocklist (169.254.169.254, 169.2... |
| CVE-2026-100704 | HIGH | 7.7 | — | Sep 26, 2026 | Kyverno is a policy engine for Kubernetes. In versions 1.14.0 through 1.19.0, the ImageValidatingPolicy (policies.kyvern... |
| CVE-2026-100703 | HIGH | 7.7 | — | Sep 26, 2026 | Kyverno 1.16.0 through 1.19.0 registers the globalcontext.Lib CEL library in its policy environment without confining it... |
| CVE-2026-100700 | HIGH | 7.5 | — | Sep 26, 2026 | nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex patter... |
| CVE-2026-100697 | HIGH | 8.6 | — | Sep 26, 2026 | Adminer 6.0.0 through 6.0.1, when the official ClickHouse driver plugin (plugins/drivers/clickhouse.php, rewritten in 6.... |
| CVE-2026-100693 | HIGH | 8.4 | — | Sep 26, 2026 | Hugo versions from v0.162.0 before v0.166.0 contain a case-sensitive validation flaw in the security.http.urls IP-litera... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now