2026 CVE Vulnerabilities
67,274 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-94107 | HIGH | 8.1 | 0.4% | Sep 20, 2026 | NivoCart through 2.4.0 contains a predictable password reset token vulnerability in the forgotten.php endpoint that gene... |
| CVE-2026-94106 | HIGH | 8.8 | 1.7% | Sep 20, 2026 | getID3 before 1.9.26 contains an OS command injection vulnerability in shell-out handlers that fail to escape filenames ... |
| CVE-2026-94105 | MEDIUM | 5.3 | 0.3% | Sep 20, 2026 | NivoCart through 2.4.0 contains a destructive configuration write vulnerability in the admin password reset controller t... |
| CVE-2026-94104 | HIGH | 8.8 | 0.7% | Sep 20, 2026 | NivoCart through 2.4.0 contains an arbitrary file upload vulnerability in the File Manager multi() endpoint that fails t... |
| CVE-2026-94004 | HIGH | 7.3 | 0.3% | Sep 20, 2026 | A vulnerability was found in DedeCMS up to 5.7.118. The affected element is an unknown function of the file plus/mytag_j... |
| CVE-2026-94003 | CRITICAL | 10 | 0.6% | Sep 20, 2026 | A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /c... |
| CVE-2026-93997 | HIGH | 7.3 | 0.3% | Sep 20, 2026 | A weakness has been identified in SourceCodester Drug Recommendation System 1.0. Affected by this issue is some unknown ... |
| CVE-2026-93980 | HIGH | 7.3 | 0.3% | Sep 20, 2026 | A weakness has been identified in code-projects Internship Management System 1.0. This vulnerability affects unknown cod... |
| CVE-2026-93979 | HIGH | 7.3 | 0.3% | Sep 20, 2026 | A security flaw has been discovered in code-projects Internship Management System 1.0. This affects an unknown part of t... |
| CVE-2026-93978 | HIGH | 7.3 | 0.3% | Sep 20, 2026 | A vulnerability was identified in code-projects Internship Management System 1.0. Affected by this issue is some unknown... |
| CVE-2026-93977 | LOW | 3.5 | 0.2% | Sep 20, 2026 | A vulnerability was determined in code-projects Assessment Management 1.0. Affected by this vulnerability is an unknown ... |
| CVE-2026-93976 | LOW | 2.4 | 0.2% | Sep 20, 2026 | A vulnerability was found in code-projects Assessment Management 1.0. Affected is an unknown function of the file admin/... |
| CVE-2026-93975 | LOW | 2.4 | 0.2% | Sep 20, 2026 | A vulnerability has been found in code-projects Assessment Management 1.0. This impacts an unknown function of the file ... |
| CVE-2026-86555 | MEDIUM | 6.2 | 0.2% | Sep 20, 2026 | The ZTE SmartLife application has a hardcoded key. The key used to decrypt account server information is stored in plain... |
| CVE-2026-93974 | HIGH | 7.3 | 0.3% | Sep 20, 2026 | A flaw has been found in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function of the f... |
| CVE-2026-93973 | HIGH | 7.3 | 0.3% | Sep 20, 2026 | A vulnerability was detected in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unknown... |
| CVE-2026-93972 | HIGH | 7.3 | 0.3% | Sep 20, 2026 | A security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0. The affected element... |
| CVE-2026-93971 | MEDIUM | 5.3 | 0.3% | Sep 20, 2026 | A weakness has been identified in aiyiyi121 SxDevOps 1.0/1.1. Impacted is an unknown function of the file backend/sxdevo... |
| CVE-2026-93970 | HIGH | 7.3 | 0.3% | Sep 20, 2026 | A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the fil... |
| CVE-2026-86554 | MEDIUM | 4.3 | 0.2% | Sep 20, 2026 | SmartLife app dynamically generates brand‑new SmartLife application authentication parameters within its runtime process... |
| CVE-2026-93969 | HIGH | 7.3 | 0.3% | Sep 20, 2026 | A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1. This vulnerability affects the function ensure_default_sup... |
| CVE-2026-93968 | LOW | 3.8 | 0.3% | Sep 20, 2026 | A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1. This affects the function update of the file backend/rbac/... |
| CVE-2026-93967 | MEDIUM | 5.5 | 0.7% | Sep 20, 2026 | A vulnerability was found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this issue is the function generate_host_task of th... |
| CVE-2026-93966 | MEDIUM | 4.7 | 1.6% | Sep 20, 2026 | A vulnerability has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this vulnerability is the function paramiko.SS... |
| CVE-2026-92965 | LOW | 3.7 | 0.2% | Sep 20, 2026 | The TikTok WordPress plugin before 1.4.2 does not check that a request is authorised before acting on a sign-in code sup... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now