2026 CVE Vulnerabilities
68,730 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-87915 | HIGH | 7.2 | — | Sep 18, 2026 | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress ... |
| CVE-2026-87743 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normal... |
| CVE-2026-18405 | HIGH | 7.2 | — | Sep 18, 2026 | The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vul... |
| CVE-2026-15797 | MEDIUM | 6.4 | 0.4% | Sep 18, 2026 | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress ... |
| CVE-2026-15579 | HIGH | 8.8 | — | Sep 18, 2026 | An out-of-bounds write vulnerability exists in some of the Ethernet switches because of improper validation of the usern... |
| CVE-2026-85410 | HIGH | 8.1 | 0.3% | Sep 18, 2026 | The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template... |
| CVE-2026-83561 | HIGH | 7.2 | — | Sep 18, 2026 | The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comm... |
| CVE-2026-6205 | HIGH | 8.1 | — | Sep 18, 2026 | An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-... |
| CVE-2026-56597 | LOW | 3.1 | — | Sep 18, 2026 | HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthe... |
| CVE-2026-56595 | LOW | 3.1 | — | Sep 18, 2026 | HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin he... |
| CVE-2026-56592 | MEDIUM | 6.5 | — | Sep 18, 2026 | HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate a... |
| CVE-2026-56590 | MEDIUM | 6.4 | — | Sep 18, 2026 | HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation c... |
| CVE-2026-4036 | MEDIUM | 6.5 | — | Sep 18, 2026 | An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Sharing API in ... |
| CVE-2026-40539 | HIGH | 7.1 | — | Sep 18, 2026 | An improper certificate validation vulnerability in Email API in Synology DiskStation Manager (DSM) before 7.2.1-69057-1... |
| CVE-2026-40538 | LOW | 3.7 | — | Sep 18, 2026 | An improper restriction of excessive authentication attempts vulnerability in Auto block in Synology DiskStation Manager... |
| CVE-2026-40537 | MEDIUM | 4.3 | — | Sep 18, 2026 | A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1-... |
| CVE-2026-40536 | MEDIUM | 4.3 | — | Sep 18, 2026 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology... |
| CVE-2026-40535 | MEDIUM | 6.5 | — | Sep 18, 2026 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synolo... |
| CVE-2026-40534 | MEDIUM | 5.4 | — | Sep 18, 2026 | An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Video API in Sy... |
| CVE-2026-40533 | MEDIUM | 5.3 | — | Sep 18, 2026 | An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (... |
| CVE-2026-40532 | MEDIUM | 6.5 | — | Sep 18, 2026 | A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-... |
| CVE-2026-40531 | MEDIUM | 4.3 | — | Sep 18, 2026 | An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-690... |
| CVE-2026-40530 | HIGH | 8 | — | Sep 18, 2026 | An improper neutralization of CRLF sequences ('CRLF injection') vulnerability in User API in Synology DiskStation Manage... |
| CVE-2026-21848 | MEDIUM | 5 | — | Sep 18, 2026 | HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticat... |
| CVE-2026-21822 | MEDIUM | 6.3 | — | Sep 18, 2026 | HCLSoftware AppScan 360° was affected by a Path Traversal vulnerability in the ASReportService component. Improper handl... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now