2026 CVE Vulnerabilities
64,704 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-67234 | LOW | 2.3 | — | Sep 25, 2026 | RabbitMQ is a messaging and streaming broker. From 4.2.0 until 4.2.8 and 4.3.2, get_auth_mechanism/1 used term_to_binary... |
| CVE-2026-66078 | LOW | 2.1 | — | Sep 25, 2026 | RabbitMQ is a messaging and streaming broker. From 3.13.0 until 3.13.15 and 4.0.20 and 4.1.11 and 4.2.6, protected tag b... |
| CVE-2026-56729 | LOW | 2.1 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, when multiple KB categories have dif... |
| CVE-2026-97868 | LOW | 3.5 | — | Sep 25, 2026 | A security vulnerability has been detected in sheshbabu zen up to 1.5.0. Affected by this issue is the function dangerou... |
| CVE-2026-96874 | LOW | 2.3 | — | Sep 25, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in the Mediawiki - Ca... |
| CVE-2026-97228 | LOW | 2.7 | — | Sep 25, 2026 | Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a GraphQL query injection issue in the export-status com... |
| CVE-2026-92106 | LOW | 2.3 | — | Sep 25, 2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dashbitco lazy_htm... |
| CVE-2026-75553 | LOW | 2.4 | — | Sep 25, 2026 | Smartphone application Tohoku Electric Power "Yorisou e Net" uses a hard-coded cryptographic key, which may allow an att... |
| CVE-2026-97721 | LOW | 2.7 | — | Sep 25, 2026 | A weakness has been identified in Sanluan PublicCMS up to 6.202506.e. This vulnerability affects the function CmsContent... |
| CVE-2026-97764 | LOW | 3.7 | — | Sep 25, 2026 | django-allauth before 65.19.4 does not have the expected limits on failed login attempts because, in some common configu... |
| CVE-2026-97233 | LOW | 3.5 | — | Sep 24, 2026 | A vulnerability was identified in volotat Anagnorisis up to 0.4.11. Affected by this issue is the function html of the f... |
| CVE-2026-63630 | LOW | 3.4 | — | Sep 24, 2026 | BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, deserializeWorkflow() accepts the Tim... |
| CVE-2026-73064 | LOW | 2.9 | — | Sep 24, 2026 | In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove o... |
| CVE-2026-19492 | LOW | 3.2 | — | Sep 24, 2026 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affe... |
| CVE-2026-77797 | LOW | 3.6 | — | Sep 24, 2026 | Velociraptor's prefetch library contains an out of bound vulnerability which may cause a crash when parsing certain malf... |
| CVE-2026-18857 | LOW | 3.4 | — | Sep 24, 2026 | IBM OPENBMC FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a v... |
| CVE-2026-18104 | LOW | 3.3 | 0.1% | Sep 24, 2026 | IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of th... |
| CVE-2026-17511 | LOW | 3.4 | — | Sep 24, 2026 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.... |
| CVE-2026-11744 | LOW | 3.8 | 0.2% | Sep 24, 2026 | An input validation vulnerability exists in the PaperCut Hive embedded application for Ricoh devices. The application fa... |
| CVE-2026-93661 | LOW | 2.7 | 0.1% | Sep 24, 2026 | The Events Manager WordPress plugin before 7.4.5 does not stop a ticket-update request from replacing the identifiers o... |
| CVE-2026-89004 | LOW | 2.7 | 0.1% | Sep 24, 2026 | The WPeMatico RSS Feed Fetcher WordPress plugin before 2.8.26 does not verify ownership or authorization before returnin... |
| CVE-2026-84151 | LOW | 3.5 | 0.2% | Sep 24, 2026 | The Post Grid WordPress plugin before 7.9.5 does not limit an expansion of the WordPress allowed-HTML list to its own m... |
| CVE-2026-96810 | LOW | 3.5 | 0.2% | Sep 24, 2026 | A vulnerability was identified in huanzi-qch base-admin up to 52816b760cd53244989fd664bbb2b3d4edbfdbf1. This issue affec... |
| CVE-2026-92628 | LOW | 3.1 | 0.1% | Sep 24, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 19.2.7, 19.3 before 19.3.3, and 1... |
| CVE-2026-67240 | LOW | 2.3 | 0.3% | Sep 23, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, pattern_to_regex maps % -> .*? and _ ->... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now