2026 CVE Vulnerabilities
64,760 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-96672 | MEDIUM | 6.4 | — | Sep 23, 2026 | Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values refere... |
| CVE-2026-79306 | MEDIUM | 6.5 | 0.3% | Sep 23, 2026 | CyberPanel v1.9.1 contains a path traversal vulnerability in the compress method exposed through the /filemanager/contro... |
| CVE-2026-79304 | MEDIUM | 6.5 | 0.4% | Sep 23, 2026 | CyberPanel 1.9.1 contains a path traversal vulnerability in the readFileContents method of the /filemanager/controller e... |
| CVE-2026-6327 | MEDIUM | 4.3 | — | Sep 23, 2026 | IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutra... |
| CVE-2026-3626 | MEDIUM | 5.3 | — | Sep 23, 2026 | IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical ... |
| CVE-2026-19267 | MEDIUM | 6.2 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rul... |
| CVE-2026-19087 | MEDIUM | 4.4 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalatio... |
| CVE-2026-18505 | MEDIUM | 5.4 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter... |
| CVE-2026-18180 | MEDIUM | 6.5 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensi... |
| CVE-2026-96611 | MEDIUM | 6.9 | 0.1% | Sep 23, 2026 | FFmpeg before 9.0 has a signed integer overflow in libavformat/mov.c. In mov_read_ispe(), uint32_t width/height values f... |
| CVE-2026-96600 | MEDIUM | 5.5 | 0.2% | Sep 23, 2026 | Isotope eCommerce through 2.9.10 contains a blind SQL injection vulnerability in backend callbacks that interpolate requ... |
| CVE-2026-96599 | MEDIUM | 5.9 | 0.4% | Sep 23, 2026 | Isotope eCommerce through 2.9.10 derives order identifiers from uniqid() instead of a cryptographically secure source, a... |
| CVE-2026-96276 | MEDIUM | 6.5 | 0.5% | Sep 23, 2026 | If a malicious SDK container declares an extension point with a crafted `directory` path, and a developer runs `flatpak ... |
| CVE-2026-92419 | MEDIUM | 5.3 | — | Sep 23, 2026 | WEBCON BPS is vulnerable to Insecure Direct Object Reference (IDOR) in the /api/vacations/{path} endpoint. The selectedP... |
| CVE-2026-92164 | MEDIUM | 6.5 | — | Sep 23, 2026 | Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.6.0, HTTPSes... |
| CVE-2026-88974 | MEDIUM | 5.4 | — | Sep 23, 2026 | WPGraphQL provides a GraphQL API for WordPress sites. Prior to 2.22.2, the updatePost mutation in src/Mutation/PostObjec... |
| CVE-2026-73858 | MEDIUM | 5.3 | — | Sep 23, 2026 | Solspace Freeform plugin for Craft CMS 5.x is a super flexible form-building tool. From 5.0.0 through 5.10.13, submitted... |
| CVE-2026-73589 | MEDIUM | 6.3 | 0.1% | Sep 23, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, Versions prior to 5.36, contains a Weak ... |
| CVE-2026-73587 | MEDIUM | 6.8 | 0.1% | Sep 23, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Certificate Validat... |
| CVE-2026-73586 | MEDIUM | 6.4 | 0.1% | Sep 23, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Insufficient Session Expirat... |
| CVE-2026-71177 | MEDIUM | 5.4 | 0.1% | Sep 23, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Restriction of Rend... |
| CVE-2026-63002 | MEDIUM | 4.8 | 0.2% | Sep 23, 2026 | REDAXO is a PHP-based content management system. Prior to 5.21.2, redaxo/src/addons/mediapool/pages/sync.php inserts fil... |
| CVE-2026-63001 | MEDIUM | 4.8 | — | Sep 23, 2026 | REDAXO is a PHP-based content management system. Prior to 5.21.2, the mediaIsInUse() handler in redaxo/src/addons/media_... |
| CVE-2026-63000 | MEDIUM | 6.4 | — | Sep 23, 2026 | REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_api_install_package_update in redaxo/src/addons/in... |
| CVE-2026-62998 | MEDIUM | 4.3 | — | Sep 23, 2026 | REDAXO is a PHP-based content management system. Prior to 5.21.2, rex_list::getSortColumn() in redaxo/src/core/lib/list.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now