2026 CVE Vulnerabilities
67,740 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54506 | HIGH | 7.6 | 0.3% | Sep 17, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5... |
| CVE-2026-54343 | HIGH | 8.7 | 0.5% | Sep 17, 2026 | Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version ... |
| CVE-2026-53557 | HIGH | 7.7 | 0.3% | Sep 17, 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated use... |
| CVE-2026-53556 | MEDIUM | 6 | 0.4% | Sep 17, 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/dat... |
| CVE-2026-53555 | MEDIUM | 5.1 | 0.4% | Sep 17, 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated upl... |
| CVE-2026-53554 | HIGH | 7.3 | 0.4% | Sep 17, 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/dat... |
| CVE-2026-53534 | HIGH | 7.5 | 0.4% | Sep 17, 2026 | JabRef is a desktop application for managing BibTeX and BibLaTeX libraries. Prior to 6.0-alpha.6, when jabsrv or JabRef'... |
| CVE-2026-50291 | MEDIUM | 5.5 | 0.2% | Sep 17, 2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a... |
| CVE-2026-50158 | HIGH | 7.7 | 0.2% | Sep 17, 2026 | yutu is an AI-powered toolkit for managing and growing YouTube channels. Prior to 0.10.9, the caption-download MCP tool ... |
| CVE-2026-16750 | MEDIUM | 5.3 | — | Sep 17, 2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of da... |
| CVE-2026-16582 | MEDIUM | 5.3 | — | Sep 17, 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modificatio... |
| CVE-2026-14311 | MEDIUM | 5.4 | — | Sep 17, 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and ... |
| CVE-2026-11432 | — | — | — | Sep 17, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-93395 | MEDIUM | 5.3 | 0.4% | Sep 17, 2026 | A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when proc... |
| CVE-2026-93394 | LOW | 3.7 | 0.3% | Sep 17, 2026 | A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and... |
| CVE-2026-93393 | HIGH | 8.1 | 0.5% | Sep 17, 2026 | A heap-based buffer overflow exists in the TLS transport layer of the MongoDB C Driver when built with the Windows platf... |
| CVE-2026-93387 | MEDIUM | 4.3 | — | Sep 17, 2026 | Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-orig... |
| CVE-2026-93386 | MEDIUM | 5.4 | — | Sep 17, 2026 | UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging soci... |
| CVE-2026-93385 | MEDIUM | 6.5 | — | Sep 17, 2026 | Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive informat... |
| CVE-2026-93384 | LOW | 3.7 | — | Sep 17, 2026 | Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker l... |
| CVE-2026-93383 | MEDIUM | 4.3 | — | Sep 17, 2026 | Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin d... |
| CVE-2026-93382 | HIGH | 8.8 | 0.3% | Sep 17, 2026 | Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code ins... |
| CVE-2026-93381 | HIGH | 8.8 | 0.3% | Sep 17, 2026 | Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.52 allowed a remote attacker leveraging soc... |
| CVE-2026-93380 | LOW | 3.1 | 0.2% | Sep 17, 2026 | Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the r... |
| CVE-2026-93379 | MEDIUM | 4.3 | 0.3% | Sep 17, 2026 | Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolatio... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now