2026 CVE Vulnerabilities
64,760 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86583 | HIGH | 8.8 | 0.3% | Sep 23, 2026 | The Import and export users and customers plugin for WordPress is vulnerable to Privilege Escalation in all versions up ... |
| CVE-2026-81537 | HIGH | 8.8 | 1.0% | Sep 23, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to... |
| CVE-2026-81536 | HIGH | 7.7 | 0.3% | Sep 23, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information ... |
| CVE-2026-81208 | HIGH | 7.7 | 0.2% | Sep 23, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow an authenticated user to access sensitive information due to imp... |
| CVE-2026-80423 | HIGH | 8.8 | 0.3% | Sep 23, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information ... |
| CVE-2026-75887 | HIGH | 7.5 | 0.4% | Sep 23, 2026 | A flaw was found in the OpenShift console. An unauthenticated attacker can exploit a path traversal vulnerability by man... |
| CVE-2026-19125 | HIGH | 8.1 | 0.6% | Sep 23, 2026 | The EthPress – Web3 Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includi... |
| CVE-2026-96556 | HIGH | 7.3 | 0.3% | Sep 23, 2026 | A flaw has been found in Neethuharii CafeManagement. Affected by this vulnerability is the function addcashier of the fi... |
| CVE-2026-82369 | HIGH | 8.6 | 0.5% | Sep 23, 2026 | Insufficient input sanitization of shell metacharacters in the Brocade SANnav CLI scripting component permits authentica... |
| CVE-2026-80425 | HIGH | 8.8 | 0.9% | Sep 23, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du... |
| CVE-2026-80412 | HIGH | 8.8 | 0.5% | Sep 23, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to... |
| CVE-2026-80379 | HIGH | 8.8 | 0.9% | Sep 23, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du... |
| CVE-2026-75886 | HIGH | 7.2 | 0.3% | Sep 23, 2026 | A flaw was found in openshift/console. An unauthenticated remote attacker can exploit a misconfiguration in the Catalogd... |
| CVE-2026-6935 | HIGH | 7.8 | 0.1% | Sep 23, 2026 | IBM Concert 1.0.0 through 3.0.0 invokes operating system commands without fully qualifying executable paths or adequatel... |
| CVE-2026-6794 | HIGH | 7.8 | 0.1% | Sep 23, 2026 | IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management. A local ... |
| CVE-2026-67235 | HIGH | 7.1 | 0.3% | Sep 23, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 4.3.0, 4.2.6, 4.1.11, 4.0.20, and 3.13.15, The content-h... |
| CVE-2026-67232 | HIGH | 8.2 | 0.4% | Sep 23, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, The cowboy We... |
| CVE-2026-66077 | HIGH | 7.3 | 0.3% | Sep 23, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6, The management UI us... |
| CVE-2026-96889 | HIGH | 7.8 | 0.1% | Sep 23, 2026 | A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate... |
| CVE-2026-96826 | HIGH | 7.6 | 0.2% | Sep 23, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shazzad Hossain Kh... |
| CVE-2026-94183 | HIGH | 7.4 | 0.2% | Sep 23, 2026 | Arc Search for Android before version 1.12.10 does not display a fullscreen notification when a page enters fullscreen m... |
| CVE-2026-86065 | HIGH | 7.5 | — | Sep 23, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /subscribe e... |
| CVE-2026-86064 | HIGH | 8.6 | — | Sep 23, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the default-open GET /log WebSock... |
| CVE-2026-85475 | HIGH | 7.2 | 0.4% | Sep 23, 2026 | A flaw was found in the Ansible Automation Platform automation controller. The external logging (rsyslog) configuration ... |
| CVE-2026-84714 | HIGH | 7.1 | 0.3% | Sep 23, 2026 | A flaw was found in the automation-controller input-validation guard sanitize_jinja(). The function us... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now