2026 CVE Vulnerabilities
64,760 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-61834 | MEDIUM | 4.3 | — | Sep 23, 2026 | scim-patch is a library for applying SCIM patch operations. Prior to 0.9.2, navigate() reads inherited properties and as... |
| CVE-2026-61413 | MEDIUM | 6.8 | 0.2% | Sep 23, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Improper Privilege Managemen... |
| CVE-2026-18179 | MEDIUM | 6.5 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to clear active chat sessions... |
| CVE-2026-84091 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | The SUMIT Payment Gateway for WooCommerce WordPress plugin before 4.0.0 does not verify with the payment provider that a... |
| CVE-2026-77112 | MEDIUM | 6.5 | — | Sep 23, 2026 | Server-Side request forgery (SSRF) vulnerability in Global IT Informatics Technology Services Inc. Weoll allows Server S... |
| CVE-2026-96446 | MEDIUM | 4.2 | 0.2% | Sep 23, 2026 | A flaw was found in the Pushed Authorization Request PAR implementation of Keycloak. The issue occurs when the silent au... |
| CVE-2026-96445 | MEDIUM | 6.8 | 0.2% | Sep 23, 2026 | A flaw was found in the Conditional OTP authenticator of Keycloak, an identity and access management solution. The issue... |
| CVE-2026-80444 | MEDIUM | 5.4 | — | Sep 23, 2026 | URL redirection to untrusted site ('open redirect') vulnerability in Abis Technology Ltd. Co. AVESİS allows Input Data M... |
| CVE-2026-73581 | MEDIUM | 6.5 | — | Sep 23, 2026 | Improper Check for Certificate Revocation vulnerability in Apache Tomcat. Both the OpenSSL and OpenSSL-FFM TLS implement... |
| CVE-2026-96456 | MEDIUM | 6.3 | — | Sep 23, 2026 | The Reachy Mini Bluetooth service asks a connecting device for a PIN before it will accept commands. The check protects ... |
| CVE-2026-90950 | MEDIUM | 5.3 | — | Sep 23, 2026 | The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not verify the reCAPTCHA on its registration handle... |
| CVE-2026-87978 | MEDIUM | 5.3 | — | Sep 23, 2026 | The Paymob for WooCommerce WordPress plugin before 4.1.14 does not verify the request signature on one branch of its pay... |
| CVE-2026-87071 | MEDIUM | 5.3 | — | Sep 23, 2026 | The Forminator Forms WordPress plugin before 1.57.2.1 does not restrict which metadata keys a form submission may supply... |
| CVE-2026-87070 | MEDIUM | 5.3 | — | Sep 23, 2026 | The Forminator Forms WordPress plugin before 1.57.2.1 does not verify that a request came from a trusted proxy before pr... |
| CVE-2026-86612 | MEDIUM | 5.6 | — | Sep 23, 2026 | The Ninja Tables WordPress plugin before 5.2.17 does not restrict shortcode expansion to administrator-authored table ro... |
| CVE-2026-86604 | MEDIUM | 4.8 | — | Sep 23, 2026 | The GTranslate WordPress plugin before 5.0.1 does not remove shortcodes from the content of outgoing emails before expan... |
| CVE-2026-86601 | MEDIUM | 6.5 | — | Sep 23, 2026 | The WP Recipe Maker WordPress plugin before 10.8.2 does not remove shortcodes from comment content before expanding it w... |
| CVE-2026-5696 | MEDIUM | 5.9 | 0.3% | Sep 23, 2026 | Reflected Cross-Site Scripting (XSS) in Microweber. The vulnerability lies in the ‘group’ parameter of the ‘/admin/setti... |
| CVE-2026-96443 | MEDIUM | 6.5 | 0.3% | Sep 23, 2026 | Insufficient validation of the JDBC driver URL in Apache Doris allows a privileged user to achieve remote code execution... |
| CVE-2026-94251 | MEDIUM | 6.5 | 0.2% | Sep 23, 2026 | A vulnerability in Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape of a resou... |
| CVE-2026-92001 | MEDIUM | 6.1 | 0.2% | Sep 23, 2026 | Improper restriction of recursive entity references in DTDs ('XML entity expansion') vulnerability in Apache Sling XSS. ... |
| CVE-2026-91999 | MEDIUM | 6.1 | 0.2% | Sep 23, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. ... |
| CVE-2026-91928 | MEDIUM | 6.1 | 0.2% | Sep 23, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. ... |
| CVE-2026-91852 | MEDIUM | 6.1 | 0.2% | Sep 23, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Apache Sling XSS. ... |
| CVE-2026-73192 | MEDIUM | 6.1 | 0.2% | Sep 23, 2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability when usin... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now