2026 CVE Vulnerabilities
65,328 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-101032 | HIGH | 7 | — | Sep 27, 2026 | navi through 2.24.0 fails to properly escape cheatsheet variable values when substituting them into shell commands. Atta... |
| CVE-2026-100872 | HIGH | 7.5 | — | Sep 27, 2026 | Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthentic... |
| CVE-2026-100871 | HIGH | 8.8 | — | Sep 27, 2026 | Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 fail to include firewall identification in JWT token... |
| CVE-2026-100870 | HIGH | 8.8 | — | Sep 27, 2026 | Sylius versions before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 build administrator password-reset links using the r... |
| CVE-2026-100869 | MEDIUM | 5.9 | — | Sep 27, 2026 | Sylius versions before 2.1.16 and 2.2.9 fail to restrict payment request actions in the Shop API endpoint, allowing cust... |
| CVE-2026-100868 | MEDIUM | 6.3 | — | Sep 27, 2026 | Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in si... |
| CVE-2026-100867 | LOW | 3.3 | — | Sep 27, 2026 | spaceship-prompt through 4.22.5 fails to sanitize control characters from project manifest version fields before renderi... |
| CVE-2026-100866 | LOW | 3.3 | — | Sep 27, 2026 | onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, ... |
| CVE-2026-97165 | MEDIUM | 5.3 | — | Sep 27, 2026 | Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0 - The “return” par... |
| CVE-2026-97164 | HIGH | 7 | 0.3% | Sep 27, 2026 | Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in `clear cache` task in Event Gallery extensio... |
| CVE-2026-100749 | MEDIUM | 5.1 | — | Sep 27, 2026 | Joomla Extension - svenbluege.de - CSRF in backend cleanup actions in Event Gallery extension < 6.5.0 - Only orphaned fi... |
| CVE-2026-100748 | MEDIUM | 6.9 | 0.2% | Sep 27, 2026 | Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.0 |
| CVE-2026-100747 | MEDIUM | 5.1 | — | Sep 27, 2026 | Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF toke... |
| CVE-2026-94417 | LOW | 2.3 | — | Sep 27, 2026 | When an application enables both OCSP and CRL revocation checking on one WOLFSSL_CTX or certificate manager, wolfSSL ski... |
| CVE-2026-93304 | MEDIUM | 6.3 | — | Sep 27, 2026 | A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. No master secret has... |
| CVE-2026-93302 | HIGH | 8.3 | — | Sep 27, 2026 | MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any ... |
| CVE-2026-89136 | HIGH | 8.3 | — | Sep 27, 2026 | When using RPK (Raw Public Key), the client side of a TLS 1.2, 1.3 and DTLS 1.2 connection could accept an unsolicited s... |
| CVE-2026-89135 | MEDIUM | 6.3 | — | Sep 27, 2026 | A failed X509_verify_cert call permanently plants an unverified attacker CA in the shared CertManager, bypassing certifi... |
| CVE-2026-89134 | MEDIUM | 6.3 | — | Sep 27, 2026 | A certificate with no dNSName SAN but another SAN type present (e.g. registeredID or iPAddress) bypassed the Subject CN ... |
| CVE-2026-89133 | MEDIUM | 6.3 | — | Sep 27, 2026 | wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509 certificate validation logic where it fails to properly e... |
| CVE-2026-89102 | HIGH | 8.3 | — | Sep 27, 2026 | In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response s... |
| CVE-2026-15442 | LOW | 2.3 | — | Sep 27, 2026 | In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS ... |
| CVE-2026-94419 | LOW | 2.3 | — | Sep 27, 2026 | Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of th... |
| CVE-2026-94418 | LOW | 2.3 | — | Sep 27, 2026 | Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate signature check separately from the parse t... |
| CVE-2026-100741 | CRITICAL | 9.8 | 1.7% | Sep 27, 2026 | Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now