2026 CVE Vulnerabilities
64,763 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-91794 | HIGH | 7.8 | 0.2% | Sep 23, 2026 | An out-of-bounds write vulnerability exists in the PDF rendering process of Foxit PDF Editor/Reader due to insufficient ... |
| CVE-2026-91793 | HIGH | 7.8 | 0.2% | Sep 23, 2026 | When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotation rich-text attribut... |
| CVE-2026-91792 | HIGH | 7.8 | 0.2% | Sep 23, 2026 | When processing a specially crafted PDF, Foxit PDF Editor/Reader may perform reentrant zoom and layout operations throug... |
| CVE-2026-91791 | HIGH | 7.8 | 0.2% | Sep 23, 2026 | When processing a specially crafted PDF file, Foxit PDF Editor/Reader may encounter a reentrant execution condition invo... |
| CVE-2026-91790 | HIGH | 7.8 | 0.2% | Sep 23, 2026 | When rendering the page image, Foxit PDF Editor/Reader fails to perform validation on image objects whose optional conte... |
| CVE-2026-91789 | HIGH | 7.8 | 0.2% | Sep 23, 2026 | Foxit PDF Editor/Reader’s U3D/GIF texture decoding path contained insufficient validation of image dimensions and relate... |
| CVE-2026-93508 | HIGH | 8.1 | 0.2% | Sep 23, 2026 | The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to its field-management AJAX acti... |
| CVE-2026-86608 | HIGH | 8.2 | 0.2% | Sep 23, 2026 | The WP Recipe Maker WordPress plugin before 10.8.2 does not have any authorisation check in one of its REST routes, nor ... |
| CVE-2026-19438 | HIGH | 7.5 | 0.4% | Sep 23, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Mint Workbench I. T... |
| CVE-2026-14321 | HIGH | 8.2 | 0.2% | Sep 23, 2026 | The divi-dash WordPress plugin before 1.0.7 does not validate the source of the client IP address it uses for rate limit... |
| CVE-2026-91777 | HIGH | 7.5 | 0.4% | Sep 23, 2026 | Forward-reference completion for @JsonIdentityInfo object IDs in FasterXML jackson-databind performs a linear scan of th... |
| CVE-2026-91776 | HIGH | 7.5 | 0.4% | Sep 23, 2026 | TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind caches the resolved deserializer under the raw, a... |
| CVE-2026-89425 | HIGH | 7.5 | 0.5% | Sep 23, 2026 | UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-core builds the offending-token text for its error me... |
| CVE-2026-95927 | HIGH | 7.3 | 0.4% | Sep 23, 2026 | A vulnerability was identified in SourceCodester Online Reviewer Management System 1.0. This affects an unknown function... |
| CVE-2026-95926 | HIGH | 7.3 | 0.4% | Sep 23, 2026 | A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. The impacted element is an unkno... |
| CVE-2026-96272 | HIGH | 7.5 | 0.3% | Sep 23, 2026 | ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability in the photo search endpoint where the quer... |
| CVE-2026-96271 | HIGH | 7.1 | 0.2% | Sep 23, 2026 | Photoview through 2.4.0 contains an authorization bypass vulnerability in the shareAlbum GraphQL mutation that allows au... |
| CVE-2026-95925 | HIGH | 7.3 | 0.4% | Sep 23, 2026 | A vulnerability was found in SourceCodester Online Reviewer Management System 1.0. The affected element is an unknown fu... |
| CVE-2026-95924 | HIGH | 7.3 | 0.3% | Sep 23, 2026 | A vulnerability has been found in SourceCodester Online Reviewer Management System 1.0. Impacted is an unknown function ... |
| CVE-2026-94367 | HIGH | 7.2 | 1.0% | Sep 23, 2026 | OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains an OS command injection vulnerability in recbackup... |
| CVE-2026-61685 | HIGH | 7.5 | 0.5% | Sep 22, 2026 | ReactPress is a publishing system for React developers. Prior to version 3.7.0, ReactPress API list endpoints build Type... |
| CVE-2026-18176 | HIGH | 7.4 | 0.2% | Sep 22, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive informati... |
| CVE-2026-18172 | HIGH | 7.4 | 0.3% | Sep 22, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive informati... |
| CVE-2026-95819 | HIGH | 7.3 | 0.4% | Sep 22, 2026 | A vulnerability has been found in anirbandutta9 College-Notes-Gallery up to 8c1cf3d98f30982d069c88ca172612c001eb39f6. Af... |
| CVE-2026-18154 | HIGH | 8 | 0.3% | Sep 22, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive informati... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now