2026 CVE Vulnerabilities
67,727 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54645 | MEDIUM | 4.8 | 1.1% | Sep 17, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, ... |
| CVE-2026-54644 | MEDIUM | 6.1 | 1.1% | Sep 17, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip... |
| CVE-2026-54643 | MEDIUM | 5.4 | 0.2% | Sep 17, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, the delete-note handler in admin/sources/orders.index.inc.ph... |
| CVE-2026-54642 | MEDIUM | 5.3 | 0.3% | Sep 17, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_card stored-... |
| CVE-2026-54634 | HIGH | 7.3 | 0.4% | Sep 17, 2026 | Hamlib is a ham radio control library for radios, rotators, and amplifiers. Prior to 4.7.2, the unauthenticated rigctld ... |
| CVE-2026-54633 | MEDIUM | 6.9 | 0.2% | Sep 17, 2026 | PoDoFo is a C++17 PDF manipulation library. From version 1.0.0 until 1.1.1, processing a crafted PDF with an Indexed col... |
| CVE-2026-54613 | MEDIUM | 5.4 | 0.2% | Sep 17, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5... |
| CVE-2026-54612 | HIGH | 8.8 | — | Sep 17, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 until... |
| CVE-2026-54608 | HIGH | 7.1 | 0.1% | Sep 17, 2026 | MythicalDash is a Pterodactyl client area. In 3.5.4-aurora and earlier, GET /api/stripe/process in backend/app/Api/Syste... |
| CVE-2026-54520 | HIGH | 8.1 | 0.5% | Sep 17, 2026 | AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior ... |
| CVE-2026-54519 | HIGH | 8.8 | 0.5% | Sep 17, 2026 | AI Agent Automation is a modular AI agent workflow automation platform with schedulers, tools, and observability. Prior ... |
| CVE-2026-54507 | HIGH | 8.4 | — | Sep 17, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5... |
| CVE-2026-54506 | HIGH | 7.6 | 0.3% | Sep 17, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5... |
| CVE-2026-54343 | HIGH | 8.7 | 0.5% | Sep 17, 2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version ... |
| CVE-2026-53557 | HIGH | 7.7 | 0.3% | Sep 17, 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated use... |
| CVE-2026-53556 | MEDIUM | 6 | 0.4% | Sep 17, 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/dat... |
| CVE-2026-53555 | MEDIUM | 5.1 | 0.4% | Sep 17, 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated upl... |
| CVE-2026-53554 | HIGH | 7.3 | 0.4% | Sep 17, 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/dat... |
| CVE-2026-53534 | HIGH | 7.5 | 0.4% | Sep 17, 2026 | JabRef is a desktop application for managing BibTeX and BibLaTeX libraries. Prior to 6.0-alpha.6, when jabsrv or JabRef'... |
| CVE-2026-50291 | MEDIUM | 5.5 | 0.2% | Sep 17, 2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a... |
| CVE-2026-50158 | HIGH | 7.7 | 0.2% | Sep 17, 2026 | yutu is an AI-powered toolkit for managing and growing YouTube channels. Prior to 0.10.9, the caption-download MCP tool ... |
| CVE-2026-16750 | MEDIUM | 5.3 | — | Sep 17, 2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of da... |
| CVE-2026-16582 | MEDIUM | 5.3 | — | Sep 17, 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modificatio... |
| CVE-2026-14311 | MEDIUM | 5.4 | — | Sep 17, 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and ... |
| CVE-2026-11432 | — | — | — | Sep 17, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now