2026 CVE Vulnerabilities
64,704 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100722 | MEDIUM | 6.8 | — | Sep 27, 2026 | vm2 before 3.12.2 does not apply host-side Promise rejection handling in the sandbox-to-host construct trap. In BaseHand... |
| CVE-2026-94408 | MEDIUM | 4.9 | — | Sep 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-... |
| CVE-2026-94400 | MEDIUM | 6.5 | — | Sep 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130) |
| CVE-2026-94399 | MEDIUM | 6.5 | — | Sep 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-... |
| CVE-2026-94398 | MEDIUM | 6.5 | — | Sep 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-... |
| CVE-2026-94397 | MEDIUM | 6.5 | — | Sep 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-... |
| CVE-2026-94396 | MEDIUM | 6.5 | — | Sep 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-... |
| CVE-2026-82300 | MEDIUM | 6.5 | — | Sep 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP... |
| CVE-2026-82294 | MEDIUM | 6.5 | — | Sep 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP... |
| CVE-2026-78582 | MEDIUM | 6.5 | — | Sep 26, 2026 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configure... |
| CVE-2026-72662 | MEDIUM | 6.3 | — | Sep 26, 2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, ... |
| CVE-2026-100719 | MEDIUM | 6.5 | — | Sep 26, 2026 | Froxlor versions before 2.3.12 contain a credential disclosure vulnerability in the DirProtections.listing API command t... |
| CVE-2026-100712 | MEDIUM | 6.5 | — | Sep 26, 2026 | froxlor through 2.3.10 disables a user's two-factor authentication immediately upon an unauthenticated-triggerable GET r... |
| CVE-2026-100710 | MEDIUM | 4.9 | — | Sep 26, 2026 | Froxlor through 2.3.10 does not filter sensitive columns from API responses: Domains::get(), Domains::listing(), SubDoma... |
| CVE-2026-100702 | MEDIUM | 5.9 | — | Sep 26, 2026 | Nodemailer before 10.0.2 fails to properly flatten deeply nested arrays in recipient fields such as to, cc, and bcc, all... |
| CVE-2026-100701 | MEDIUM | 5.9 | — | Sep 26, 2026 | Nodemailer versions 5.0.0 through 10.0.1 use a process-global DNS cache that is keyed only by the DNS host, while each c... |
| CVE-2026-100699 | MEDIUM | 5.3 | — | Sep 26, 2026 | Nodemailer is a Node.js email-sending library. In versions >= 9.1.0 and < 10.0.9, the address parser (src/addressparser)... |
| CVE-2026-100698 | MEDIUM | 5.8 | — | Sep 26, 2026 | Adminer 5.5.1 through 6.0.1 improperly parses the login 'server' string in the host_port() function in adminer/include/f... |
| CVE-2026-100696 | MEDIUM | 5.8 | — | Sep 26, 2026 | Adminer 4.16.0 through 6.0.1 contain a pre-authentication Server-Side Request Forgery (SSRF) vulnerability in the option... |
| CVE-2026-100695 | MEDIUM | 6.1 | — | Sep 26, 2026 | Adminer before 6.0.2 contains a cross-site scripting vulnerability where the CONNECTION_ID() database result is interpol... |
| CVE-2026-100694 | MEDIUM | 6.1 | — | Sep 26, 2026 | Hugo is a static site generator. In versions from v0.56.0 through v0.165.x, content files mapped to the text/org media t... |
| CVE-2026-100691 | MEDIUM | 5.4 | — | Sep 26, 2026 | Hugo versions 0.75.0 through 0.165.x contain a stored cross-site scripting vulnerability: the syntax highlighter does no... |
| CVE-2026-100689 | MEDIUM | 5.9 | — | Sep 26, 2026 | GitPython before 3.1.62 does not validate the `path` field read from an untrusted .gitmodules file when updating submodu... |
| CVE-2026-100688 | MEDIUM | 6.5 | — | Sep 26, 2026 | Budibase server before 3.45.0 contains a cross-tenant information disclosure vulnerability in the GET /api/applications/... |
| CVE-2026-100687 | MEDIUM | 5.5 | — | Sep 26, 2026 | Budibase Server before 3.45.0 fails to redact plaintext datasource credentials before broadcasting external table update... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now