2026 CVE Vulnerabilities
64,760 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4638 | HIGH | 7.1 | — | Sep 24, 2026 | PRTG Network Monitor before version 26.2.120.1449 ships a demo EXE/Script sensor that multiplies two integer parameters ... |
| CVE-2026-57590 | HIGH | 8.1 | 0.2% | Sep 24, 2026 | A missing authorization vulnerability exists in the Task Group APIs of Apache DolphinScheduler. The affected APIs do not... |
| CVE-2026-97185 | HIGH | 7.8 | 0.1% | Sep 24, 2026 | A flaw was found in GIMP. When processing a specially crafted GIMPressionist preset file, the plug-in does not properly ... |
| CVE-2026-85682 | HIGH | 8.8 | 0.1% | Sep 24, 2026 | The YOP Poll plugin for WordPress is vulnerable to Origin Validation Error in all versions up to, and including, 7.0.10.... |
| CVE-2026-78311 | HIGH | 8.8 | 0.2% | Sep 24, 2026 | SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. |
| CVE-2026-78309 | HIGH | 8.8 | 0.2% | Sep 24, 2026 | SQL Injection vulnerability in DIAEnergie. This issue affects DIAEnergie: before 1.11.00.022. |
| CVE-2026-77193 | HIGH | 7.5 | 0.4% | Sep 24, 2026 | The eesy_ID2WP – Publish InDesign HTML5 plugin for WordPress is vulnerable to Path Traversal in all versions up to, and ... |
| CVE-2026-82077 | HIGH | 7.3 | 0.7% | Sep 24, 2026 | An improper limitation of a pathname to a restricted directory (path traversal) vulnerability in the Scan-to-Fax compone... |
| CVE-2026-88843 | HIGH | 7.2 | 0.2% | Sep 24, 2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not validate one of its display-style settings... |
| CVE-2026-80513 | HIGH | 7.5 | 0.2% | Sep 24, 2026 | The wpForo Forum WordPress plugin before 3.1.6 does not restrict which classes may be instantiated when it deserializes ... |
| CVE-2026-14780 | HIGH | 7.5 | 0.3% | Sep 24, 2026 | A vulnerability exists in the PaperCut NG/MF platform's device-scripting functionality due to insufficient sanitization ... |
| CVE-2026-97152 | HIGH | 8.6 | 0.3% | Sep 24, 2026 | Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely exploitable buffer overflow in the WebSocket transport... |
| CVE-2026-97151 | HIGH | 8.4 | 0.4% | Sep 24, 2026 | mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a documen... |
| CVE-2026-96898 | HIGH | 7.3 | 0.4% | Sep 24, 2026 | A vulnerability was detected in yhx070424 ShopXO up to 2.2.7. Affected by this vulnerability is an unknown functionality... |
| CVE-2026-97055 | HIGH | 8.1 | 0.4% | Sep 24, 2026 | SigNoz from v0.8.0 before v0.143.0 defaults the JWT tokenizer signing secret (tokenizer::jwt::secret, set via SIGNOZ_TOK... |
| CVE-2026-96803 | HIGH | 7.3 | 0.3% | Sep 24, 2026 | A vulnerability was identified in java110 MicroCommunity up to 2.0. Affected is the function QueryServiceSMOImpl.fallBac... |
| CVE-2026-96762 | HIGH | 7.3 | 0.3% | Sep 24, 2026 | A vulnerability was determined in kvcache-ai mooncake up to 0.3.12/0.3.13.post1. This affects the function UnmountSegmen... |
| CVE-2026-96751 | HIGH | 7.3 | 0.3% | Sep 24, 2026 | A vulnerability has been found in pmTicket Project-Management-Software up to 078fa56a782490c5059a0814f84df27984f4d7e2. T... |
| CVE-2026-92470 | HIGH | 7.7 | 0.2% | Sep 24, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 19.2.7, 19.3 before 19.3.3, and 19.4... |
| CVE-2026-82370 | HIGH | 8.6 | 0.6% | Sep 24, 2026 | Unauthenticated remote command injection in the Brocade SANnav orchestrator HTTP service permits network-adjacent attack... |
| CVE-2026-70125 | HIGH | 8.8 | 0.4% | Sep 23, 2026 | Microsoft Office Outlook Remote Code Execution Vulnerability |
| CVE-2026-96604 | HIGH | 7.3 | 0.3% | Sep 23, 2026 | A vulnerability was identified in SoftNews Media Group DataLife Engine 18.0. This affects the function strip_data of the... |
| CVE-2026-96603 | HIGH | 7.3 | 0.3% | Sep 23, 2026 | A vulnerability has been found in Abdurrab5 online-makeup-store. Affected is the function confirm_logged_in/confirm_user... |
| CVE-2026-96602 | HIGH | 7.3 | 0.3% | Sep 23, 2026 | A flaw has been found in Abdurrab5 online-makeup-store. This impacts an unknown function of the file customerSignin.php ... |
| CVE-2026-96601 | HIGH | 7.3 | 0.3% | Sep 23, 2026 | A vulnerability was detected in Abdurrab5 online-makeup-store. This affects an unknown function of the file index.php of... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now