2026 CVE Vulnerabilities
64,760 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84706 | HIGH | 7.6 | 0.3% | Sep 23, 2026 | A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable... |
| CVE-2026-84691 | HIGH | 8.7 | 0.2% | Sep 23, 2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The setting that formats the log messa... |
| CVE-2026-84683 | HIGH | 8.7 | 0.3% | Sep 23, 2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of job, ad hoc command, ... |
| CVE-2026-82409 | HIGH | 8.4 | 0.3% | Sep 23, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, indexer/common.go serializedDataF... |
| CVE-2026-82407 | HIGH | 7 | — | Sep 23, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, core/kapp/validators/validators.g... |
| CVE-2026-82406 | HIGH | 7.1 | 0.3% | Sep 23, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the native marketplace function c... |
| CVE-2026-82405 | HIGH | 8.7 | 0.3% | Sep 23, 2026 | Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, the KleverUpdateAccountPermission... |
| CVE-2026-68492 | HIGH | 8.7 | 0.4% | Sep 23, 2026 | An untrusted search path vulnerability in Plesk from 18.0.34 before 18.0.80.8 and 18.0.81 before 18.0.81.1 allows remote... |
| CVE-2026-68490 | HIGH | 8.2 | 0.1% | Sep 23, 2026 | Incorrect permission assignment allows local users to obtain sensitive CalDAV/CardDAV information belonging to other acc... |
| CVE-2026-67238 | HIGH | 7.1 | 0.3% | Sep 23, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 4.2.7 and 4.3.1, rabbit_pid_codec:decompose_from_binary/... |
| CVE-2026-66079 | HIGH | 8.2 | 0.3% | Sep 23, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6, parse_array_primitiv... |
| CVE-2026-66070 | HIGH | 7.6 | 0.4% | Sep 23, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.17, 4.0.22, 4.1.13, and 4.2.6, match_origin/1 retur... |
| CVE-2026-96541 | HIGH | 7.5 | 0.8% | Sep 23, 2026 | A denial-of-service flaw was found in gnome-remote-desktop. An unauthenticated remote attacker can open RDP connections ... |
| CVE-2026-95604 | HIGH | 7.5 | — | Sep 23, 2026 | Unauthenticated Broken Access Control in Loops & Logic <= 4.2.4 versions. |
| CVE-2026-95603 | HIGH | 7.2 | — | Sep 23, 2026 | Shop manager PHP Object Injection in Reycob Product Import Export <= 2.3.0 versions. |
| CVE-2026-95593 | HIGH | 7.6 | — | Sep 23, 2026 | Editor SQL Injection in Ultimeter <= 3.0.8 versions. |
| CVE-2026-95590 | HIGH | 7.1 | — | Sep 23, 2026 | Subscriber SQL Injection in Tainacan <= 1.2.0 versions. |
| CVE-2026-95529 | HIGH | 7.1 | — | Sep 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in Calculated Fields Form <= 5.5.1.1 versions. |
| CVE-2026-95528 | HIGH | 7.1 | — | Sep 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in Core Web Vitals & PageSpeed Booster <= 1.0.31 versions. |
| CVE-2026-95522 | HIGH | 7.6 | — | Sep 23, 2026 | Shop manager SQL Injection in Easy Digital Downloads <= 3.7.0 versions. |
| CVE-2026-95515 | HIGH | 7.1 | — | Sep 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in Ninja Forms <= 3.15.3 versions. |
| CVE-2026-95513 | HIGH | 7.5 | — | Sep 23, 2026 | Unauthenticated Broken Access Control in Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 versions. |
| CVE-2026-94487 | HIGH | 8.1 | — | Sep 23, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Capabilities <= 2.50.1 versions. |
| CVE-2026-94181 | HIGH | 7.4 | 0.3% | Sep 23, 2026 | An address bar spoofing issue in affected versions of Arc could allow an attacker to spoof the browser address bar via a... |
| CVE-2026-94179 | HIGH | 7.1 | — | Sep 23, 2026 | Unauthenticated Cross Site Scripting (XSS) in Razorpay Payment Button <= 2.4.9 versions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now