2026 CVE Vulnerabilities
64,760 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-92284 | MEDIUM | 6.9 | — | Sep 23, 2026 | Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, in modules/caddyhttp/rep... |
| CVE-2026-90900 | MEDIUM | 5.3 | — | Sep 23, 2026 | Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Storefront Product Review Submission in Easy Stor... |
| CVE-2026-77421 | MEDIUM | 6.5 | — | Sep 23, 2026 | JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in nano editor's... |
| CVE-2026-77420 | MEDIUM | 5.5 | — | Sep 23, 2026 | JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, DefaultHistory.matchPatterns(Str... |
| CVE-2026-71462 | MEDIUM | 4.1 | — | Sep 23, 2026 | StringListPathField.to_internal_value() calls os.path.exists() on unbounded user-supplied paths. ... |
| CVE-2026-71461 | MEDIUM | 4.3 | 0.2% | Sep 23, 2026 | HostList.list() catches bare Exception and returns str(e) verbatim. Via host_filter, any authenticated use... |
| CVE-2026-71460 | MEDIUM | 4.3 | — | Sep 23, 2026 | /api/v2/config/ is protected only by IsAuthenticated. license_info (account_number, subscription_id, pool_... |
| CVE-2026-71459 | MEDIUM | 5 | 0.3% | Sep 23, 2026 | JobJobEventsChildrenSummary view has no model/parent_model. ModelAccessPermission.check_get_permissions() ... |
| CVE-2026-71458 | MEDIUM | 5 | — | Sep 23, 2026 | URLModificationMiddleware resolves named-URL lookups against unfiltered Model.objects before RBAC. The 403... |
| CVE-2026-63131 | MEDIUM | 6 | 0.4% | Sep 23, 2026 | OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's vault/policy/acl.go could ... |
| CVE-2026-55632 | MEDIUM | 4.3 | — | Sep 23, 2026 | GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal pipeline structure API used for autocompleti... |
| CVE-2026-52744 | MEDIUM | 5.3 | — | Sep 23, 2026 | GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API a... |
| CVE-2026-88840 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message. |
| CVE-2026-88839 | MEDIUM | 6.7 | 0.1% | Sep 23, 2026 | BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of he... |
| CVE-2026-88837 | MEDIUM | 6.5 | 0.2% | Sep 23, 2026 | BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authenticati... |
| CVE-2026-88835 | MEDIUM | 6.1 | 0.1% | Sep 23, 2026 | BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap ... |
| CVE-2026-88831 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the ru... |
| CVE-2026-86867 | MEDIUM | 6.5 | 0.1% | Sep 23, 2026 | Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-user chat interface contains multiple vulnerabiliti... |
| CVE-2026-96807 | MEDIUM | 4 | 0.1% | Sep 23, 2026 | In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regener... |
| CVE-2026-96655 | MEDIUM | 4.3 | — | Sep 23, 2026 | Plex Media Server before 1.43.3.10861 allows an authenticated user to request arbitrary internal or external addresses v... |
| CVE-2026-96654 | MEDIUM | 6.5 | — | Sep 23, 2026 | Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an atta... |
| CVE-2026-96652 | MEDIUM | 4.3 | — | Sep 23, 2026 | Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can i... |
| CVE-2026-96651 | MEDIUM | 6.5 | — | Sep 23, 2026 | Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, a... |
| CVE-2026-6669 | MEDIUM | 5.9 | — | Sep 23, 2026 | Missing upper bound on the key derivation iteration count accepted during SCRAM authentication to a backend server in Pg... |
| CVE-2026-96674 | MEDIUM | 4.4 | 0.1% | Sep 23, 2026 | alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowin... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now