2026 CVE Vulnerabilities
67,720 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-17086 | HIGH | 8.8 | — | Sep 18, 2026 | The ShortPixel Image Optimizer – Optimize Images, Convert WebP & AVIF plugin for WordPress is vulnerable to PHP Object I... |
| CVE-2026-93468 | HIGH | 7.5 | — | Sep 18, 2026 | The OAKlouds developed by HGiga has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit R... |
| CVE-2026-93467 | CRITICAL | 9.8 | — | Sep 18, 2026 | The OAKlouds developed by HGiga has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execu... |
| CVE-2026-93371 | HIGH | 8.3 | 1.4% | Sep 18, 2026 | A security vulnerability has been detected in marcopiovanello yt-dlp-web-ui up to v4. This issue affects the function Ne... |
| CVE-2026-92991 | MEDIUM | 5.4 | — | Sep 18, 2026 | The Biggop Library is vulnerable to Cross-Site Scripting via the ‘display_id’ parameter from the Sigmative API in variou... |
| CVE-2026-15650 | MEDIUM | 6.4 | — | Sep 18, 2026 | The RT Mega Menu – Mega Menu Builder for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site S... |
| CVE-2026-14855 | MEDIUM | 6.4 | — | Sep 18, 2026 | The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all ... |
| CVE-2026-93456 | HIGH | 8.2 | 0.2% | Sep 18, 2026 | django-page-cms through 2.0.13 exempts five admin mutation views from CSRF protection in pages/admin/views.py, allowing ... |
| CVE-2026-93455 | MEDIUM | 6.5 | 0.3% | Sep 18, 2026 | django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff acc... |
| CVE-2026-93331 | HIGH | 7.3 | — | Sep 18, 2026 | A vulnerability was identified in GPAC 26.08-DEV. This vulnerability affects the function gf_rtp_parse_ttxt of the file ... |
| CVE-2026-93314 | MEDIUM | 6.3 | 0.2% | Sep 18, 2026 | A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of t... |
| CVE-2026-93313 | MEDIUM | 6.3 | — | Sep 18, 2026 | A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTabl... |
| CVE-2026-82985 | MEDIUM | 6.5 | — | Sep 18, 2026 | The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolder... |
| CVE-2026-82982 | MEDIUM | 4.3 | — | Sep 18, 2026 | The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing ... |
| CVE-2026-82980 | MEDIUM | 6.3 | — | Sep 18, 2026 | Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The D... |
| CVE-2026-77170 | MEDIUM | 4.3 | — | Sep 18, 2026 | The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without va... |
| CVE-2026-77169 | MEDIUM | 6.5 | — | Sep 18, 2026 | A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed... |
| CVE-2026-77164 | MEDIUM | 6.2 | — | Sep 18, 2026 | Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote insta... |
| CVE-2026-68493 | LOW | 3.1 | — | Sep 18, 2026 | After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships ... |
| CVE-2026-93312 | MEDIUM | 4.3 | 0.3% | Sep 18, 2026 | A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/J... |
| CVE-2026-93311 | MEDIUM | 4.3 | 0.3% | Sep 18, 2026 | A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFun... |
| CVE-2026-93310 | MEDIUM | 5.3 | — | Sep 18, 2026 | A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collect... |
| CVE-2026-79954 | HIGH | 8.7 | — | Sep 18, 2026 | NASA CryptoLib 1.5.0 contains an authentication downgrade vulnerability in the Telecommand (TC) receive path. The receiv... |
| CVE-2026-93454 | MEDIUM | 5.4 | 0.2% | Sep 18, 2026 | Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plu... |
| CVE-2026-93453 | HIGH | 8.3 | 0.3% | Sep 18, 2026 | SOGo before 5.12.11 constructs password-reset links using the client-supplied Origin header as the authority, allowing u... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now