2026 CVE Vulnerabilities
64,760 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-67219 | MEDIUM | 6 | 0.3% | Sep 23, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, add_binding/3... |
| CVE-2026-66080 | MEDIUM | 5.9 | 0.3% | Sep 23, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 4.1.11, 4.2.6, and 4.3.0, validate_partitions only check... |
| CVE-2026-66074 | MEDIUM | 6 | 0.3% | Sep 23, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, match_value/3... |
| CVE-2026-66072 | MEDIUM | 6 | 0.3% | Sep 23, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, get_chunk_sel... |
| CVE-2026-66068 | MEDIUM | 5.6 | 0.1% | Sep 23, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, ?LOG_DEBUG("s... |
| CVE-2026-66067 | MEDIUM | 6 | 0.4% | Sep 23, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, The stream open handler calls only chec... |
| CVE-2026-96551 | MEDIUM | 4.3 | 0.2% | Sep 23, 2026 | A vulnerability was determined in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Impacted is an unk... |
| CVE-2026-84724 | MEDIUM | 6.6 | 0.3% | Sep 23, 2026 | An argument-injection flaw was found in the Ansible Automation Platform automation-controller system-job subsystem. The ... |
| CVE-2026-84721 | MEDIUM | 6.4 | 0.2% | Sep 23, 2026 | A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification... |
| CVE-2026-84720 | MEDIUM | 6.5 | 0.3% | Sep 23, 2026 | A flaw was found in the Ansible Automation Platform automation-controller. The WorkflowJobNode.ancestor_artifacts databa... |
| CVE-2026-84718 | MEDIUM | 4.3 | 0.1% | Sep 23, 2026 | A flaw was found in the Ansible Automation Platform automation-controller. In the shipped production configuration, the ... |
| CVE-2026-84717 | MEDIUM | 5.3 | 0.3% | Sep 23, 2026 | A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center web... |
| CVE-2026-84716 | MEDIUM | 6.6 | 0.2% | Sep 23, 2026 | A flaw was found in the automation-controller instance install-bundle endpoint. When a System Administ... |
| CVE-2026-84713 | MEDIUM | 6.5 | 0.3% | Sep 23, 2026 | A flaw was found in the automation-controller notification subsystem. Although NotificationTemplate.no... |
| CVE-2026-84712 | MEDIUM | 5.3 | 0.3% | Sep 23, 2026 | A flaw was found in the automation-controller API. The unauthenticated health-check endpoint /api/v2/p... |
| CVE-2026-96548 | MEDIUM | 5.6 | — | Sep 23, 2026 | A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects an unknown par... |
| CVE-2026-96545 | MEDIUM | 4.4 | 0.2% | Sep 23, 2026 | An out-of-bounds heap read flaw was found in GIMP's TIM image loader. When a user opens a crafted 4bpp TIM image that ca... |
| CVE-2026-95602 | MEDIUM | 6.5 | — | Sep 23, 2026 | Authorization Bypass Through User-Controlled Key vulnerability in YITH YITH WooCommerce Request A Quote allows Exploitin... |
| CVE-2026-95600 | MEDIUM | 5.3 | — | Sep 23, 2026 | Unauthenticated Sensitive Data Exposure in TrustedLogin Connector <= 2.0.3 versions. |
| CVE-2026-95592 | MEDIUM | 5.3 | — | Sep 23, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in Team <= 6.0.0 versions. |
| CVE-2026-95586 | MEDIUM | 6.5 | — | Sep 23, 2026 | Contributor Cross Site Scripting (XSS) in Ultimate Addons for Contact Form 7 <= 3.5.50 versions. |
| CVE-2026-95530 | MEDIUM | 6.5 | — | Sep 23, 2026 | Subscriber Cross Site Scripting (XSS) in PixelYourSite – Your smart PIXEL (TAG) Manager <= 11.4.1 versions. |
| CVE-2026-95527 | MEDIUM | 6.5 | — | Sep 23, 2026 | Unauthenticated Broken Access Control in Conekta Payment Gateway <= 6.2.4 versions. |
| CVE-2026-95525 | MEDIUM | 6.5 | — | Sep 23, 2026 | Subscriber Arbitrary File Deletion in WP User Frontend <= 4.3.11 versions. |
| CVE-2026-95524 | MEDIUM | 5.3 | — | Sep 23, 2026 | Unauthenticated Bypass Vulnerability in WP User Frontend <= 4.3.11 versions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now