2026 CVE Vulnerabilities
64,704 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-67224 | LOW | 2.1 | 0.4% | Sep 23, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, The trace con... |
| CVE-2026-67218 | LOW | 2.1 | 0.3% | Sep 23, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 4.0.22, 4.1.11, 4.2.6, and 4.3.0, accept_content/2 at li... |
| CVE-2026-66075 | LOW | 2.3 | 0.2% | Sep 23, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, is_authorized... |
| CVE-2026-66069 | LOW | 2.3 | 0.4% | Sep 23, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 4.1.13, 4.2.7, and 4.3.0, is_authorized/2 uses is_author... |
| CVE-2026-96552 | LOW | 3.1 | 0.2% | Sep 23, 2026 | A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected eleme... |
| CVE-2026-96550 | LOW | 3.7 | 0.2% | Sep 23, 2026 | A vulnerability was found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This issue affects the ... |
| CVE-2026-66076 | LOW | 2.3 | 0.3% | Sep 23, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.0, is_authorized... |
| CVE-2026-96872 | LOW | 2.9 | 0.2% | Sep 23, 2026 | Improper handling of insufficient permissions or privileges vulnerability in The Wikimedia Foundation Mediawiki - WikiLa... |
| CVE-2026-96549 | LOW | 3.3 | — | Sep 23, 2026 | A vulnerability has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This vulnerability... |
| CVE-2026-96546 | LOW | 2.5 | 0.1% | Sep 23, 2026 | A one-byte out-of-bounds heap read flaw was found in GIMP's uncompressed DDS image loader. When a user opens an uncompre... |
| CVE-2026-77285 | LOW | 2.4 | — | Sep 23, 2026 | OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao Agent's exec rendering mode ... |
| CVE-2026-71465 | LOW | 3.1 | 0.2% | Sep 23, 2026 | RunAdHocCommand.build_args() appends limit as bare positional (args.append(limit)) instead of using ... |
| CVE-2026-71464 | LOW | 3.1 | 0.2% | Sep 23, 2026 | LaunchConfigurationBaseSerializer.scm_branch has no validate_scm_branch() leading-dash check, unlike ... |
| CVE-2026-71463 | LOW | 2.7 | 0.3% | Sep 23, 2026 | Notification template Jinja AST whitelist only inspects static Getattr nodes. Dynamic subscripts (job['job... |
| CVE-2026-96675 | LOW | 3.3 | 0.1% | Sep 23, 2026 | alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate spar... |
| CVE-2026-4921 | LOW | 2.7 | — | Sep 23, 2026 | IBM Guardium Data Protection 12.2 could allow an administrative user to obtain sensitive information when a detailed tec... |
| CVE-2026-71178 | LOW | 3.7 | 0.2% | Sep 23, 2026 | Dell Secure Connect Gateway (SCG) Policy Manager, versions prior to 5.34.00.16, contains an Use of Non-Canonical URL Pat... |
| CVE-2026-78253 | LOW | 2.3 | 0.3% | Sep 23, 2026 | Uncontrolled recursion in QXmlStreamReader::readElementText() in Qt Group Qt allows attackers to cause a denial of servi... |
| CVE-2026-77756 | LOW | 3.7 | — | Sep 23, 2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat caused b... |
| CVE-2026-87848 | LOW | 3.7 | — | Sep 23, 2026 | The MPCX Lightbox WordPress plugin 1.2.2 through 1.2.5 does not have any authorisation or authentication on one of its A... |
| CVE-2026-79616 | LOW | 0.6 | 0.1% | Sep 23, 2026 | Out-of-bounds read while parsing untrusted SVG path strings in Qt Quick's Context2D.path / PathSvg.path. |
| CVE-2026-93528 | LOW | 3.7 | 0.2% | Sep 23, 2026 | The NP Quote Request for WooCommerce WordPress plugin before 2.4.16 does not verify order ownership before rendering an ... |
| CVE-2026-93507 | LOW | 3.3 | 0.2% | Sep 23, 2026 | The WC Fields Factory WordPress plugin before 4.1.11 does not properly restrict access to, or verify a nonce for, a post... |
| CVE-2026-91077 | LOW | 2.7 | 0.2% | Sep 23, 2026 | The Event Booking Manager for WooCommerce WordPress plugin before 5.7.3 does not restrict its event listing query to ev... |
| CVE-2026-90951 | LOW | 3.7 | 0.2% | Sep 23, 2026 | The Paid Membership Subscriptions WordPress plugin before 3.1.0 does not bind one of its unauthenticated payment action... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now