2026 CVE Vulnerabilities
64,760 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85458 | LOW | 2.1 | 0.1% | Sep 3, 2026 | Divide-by-zero in Xpdf 4.06 (and earlier), when a glyph in a Type 3 font has a zero height. |
| CVE-2026-85207 | LOW | 3.5 | 0.2% | Sep 3, 2026 | A vulnerability was identified in itsourcecode Online Medicine Delivery System 1.0. Impacted is an unknown function of t... |
| CVE-2026-85052 | LOW | 3.1 | 0.2% | Sep 3, 2026 | Out of bounds read in CrashReporting in Google Chrome prior to 152.0.7977.82 allowed a remote attacker who had compromis... |
| CVE-2026-49456 | LOW | 3.1 | 0.3% | Sep 3, 2026 | Waku is the minimal React framework. Prior to version 1.0.0-beta.1, the unstable_redirect() helper exported from waku/ro... |
| CVE-2026-84969 | LOW | 3.7 | 0.2% | Sep 3, 2026 | A memory-handling error in the BSON-to-JSON conversion helpers of the MongoDB C Driver can write a small number of bytes... |
| CVE-2026-85030 | LOW | 3.7 | 0.4% | Sep 3, 2026 | A vulnerability has been found in HKUDS AI-Trader up to d03ff6c056b32ced735adf7c19ed8175adb1c8df. The affected element i... |
| CVE-2026-85022 | LOW | 3.5 | 0.3% | Sep 3, 2026 | A vulnerability was identified in langgenius dify 1.13.0. Affected by this vulnerability is the function router.replace ... |
| CVE-2026-84653 | LOW | 3.5 | 0.2% | Sep 2, 2026 | Jenkins 2.421 through 2.579 (both inclusive), LTS 2.426.1 through 2.568.2 (both inclusive) does not correctly perform pe... |
| CVE-2026-63020 | LOW | 3.1 | 0.2% | Sep 2, 2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error mes... |
| CVE-2026-78600 | LOW | 3.5 | 0.2% | Sep 2, 2026 | Incomplete Cleanup (CWE-459) in Elastic Cloud on Kubernetes (ECK) can lead to unauthorized access via Privilege Abuse (C... |
| CVE-2026-78587 | LOW | 3.1 | 0.2% | Sep 2, 2026 | Incorrect Authorization (CWE-863) in Fleet Server can lead to a denial of service of agent upload operations via Privile... |
| CVE-2026-19698 | LOW | 3.5 | 0.2% | Sep 2, 2026 | The GutenKit WordPress plugin before 2.5.1 does not validate or escape style settings saved against a post before using ... |
| CVE-2026-14326 | LOW | 3.8 | 0.2% | Sep 2, 2026 | The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through it... |
| CVE-2026-81168 | LOW | 3.7 | 0.3% | Sep 2, 2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal CAPTCHA Protected Page allows Functiona... |
| CVE-2026-81161 | LOW | 3.3 | 0.2% | Sep 2, 2026 | Privilege Defined With Unsafe Actions vulnerability in Drupal Content Moderation Notifications allows Privilege Escalati... |
| CVE-2026-81159 | LOW | 3.7 | 0.3% | Sep 2, 2026 | Observable Timing Discrepancy vulnerability in Drupal Commerce CyberSource allows Brute Force. This issue affects Commer... |
| CVE-2026-81198 | LOW | 3.8 | 0.2% | Sep 2, 2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of a curriculum ... |
| CVE-2026-81196 | LOW | 2.7 | 0.2% | Sep 2, 2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify ownership of quiz question... |
| CVE-2026-77787 | LOW | 2.7 | 0.2% | Sep 2, 2026 | The Rank Math SEO WordPress plugin before 1.0.277 does not perform a capability check when bulk metadata updates target... |
| CVE-2026-77785 | LOW | 2.7 | 0.2% | Sep 2, 2026 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the requesting user is permitted to read the spe... |
| CVE-2026-77784 | LOW | 2.7 | 0.2% | Sep 2, 2026 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that a user is allowed to edit the object being modif... |
| CVE-2026-77783 | LOW | 3.7 | 0.2% | Sep 2, 2026 | The Rank Math SEO WordPress plugin before 1.0.277 does not verify that the post whose schema it renders on the front en... |
| CVE-2026-84438 | LOW | 3.5 | — | Sep 2, 2026 | A vulnerability was determined in OpenCart 4.1.0.3/4.1.0.4. This affects an unknown function of the file catalog/control... |
| CVE-2026-84437 | LOW | 3.5 | 0.2% | Sep 2, 2026 | A vulnerability was found in OpenCart 4.1.0.3/4.1.0.4. The impacted element is an unknown function of the file catalog/c... |
| CVE-2026-84359 | LOW | 3.1 | 0.1% | Sep 2, 2026 | Information leak in Skia in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the rende... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now