2026 CVE Vulnerabilities
65,368 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100740 | CRITICAL | 9.9 | — | Sep 27, 2026 | A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel... |
| CVE-2026-100739 | HIGH | 7.3 | — | Sep 26, 2026 | A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. ... |
| CVE-2026-94408 | MEDIUM | 4.9 | — | Sep 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-... |
| CVE-2026-94400 | MEDIUM | 6.5 | — | Sep 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130) |
| CVE-2026-94399 | MEDIUM | 6.5 | — | Sep 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-... |
| CVE-2026-94398 | MEDIUM | 6.5 | — | Sep 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-... |
| CVE-2026-94397 | MEDIUM | 6.5 | — | Sep 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-... |
| CVE-2026-94396 | MEDIUM | 6.5 | — | Sep 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-... |
| CVE-2026-82300 | MEDIUM | 6.5 | — | Sep 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP... |
| CVE-2026-82294 | MEDIUM | 6.5 | — | Sep 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP... |
| CVE-2026-78582 | MEDIUM | 6.5 | — | Sep 26, 2026 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configure... |
| CVE-2026-72668 | HIGH | 7.3 | — | Sep 26, 2026 | Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation.... |
| CVE-2026-72662 | MEDIUM | 6.3 | — | Sep 26, 2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, ... |
| CVE-2026-82901 | CRITICAL | 9.8 | — | Sep 26, 2026 | The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file... |
| CVE-2026-85984 | CRITICAL | 9.8 | — | Sep 26, 2026 | The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass... |
| CVE-2026-77203 | HIGH | 8.8 | — | Sep 26, 2026 | The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalation in all versions u... |
| CVE-2026-97163 | CRITICAL | 10 | — | Sep 26, 2026 | Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 |
| CVE-2026-97162 | HIGH | 8.3 | — | Sep 26, 2026 | Joomla Extension - lomart.fr - Various SQL injection vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 |
| CVE-2026-97161 | CRITICAL | 9.2 | — | Sep 26, 2026 | Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.... |
| CVE-2026-97160 | CRITICAL | 9.4 | — | Sep 26, 2026 | Joomla Extension - lomart.fr - Authenticated, privileged PHP command injection in UP plugin extension 5.0.0-5.2.0, 6.0.0... |
| CVE-2026-94132 | CRITICAL | 9.5 | — | Sep 26, 2026 | Joomla Extension - acymailing.com - Remote Code Execution vulnerability in mailbox action feature in AcyMailing Enterpri... |
| CVE-2026-94131 | HIGH | 8.3 | — | Sep 26, 2026 | Joomla Extension - acymailing.com - Unauthenticated arbitrary file deletion in AcyMailing Enterprise extension < 11.1.0 ... |
| CVE-2026-94130 | CRITICAL | 9.3 | — | Sep 26, 2026 | Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injectio... |
| CVE-2026-100720 | HIGH | 8.7 | — | Sep 26, 2026 | Froxlor 2.0.0 through 2.3.10 is vulnerable to stored cross-site scripting. When a customer (the lowest-privileged authen... |
| CVE-2026-100719 | MEDIUM | 6.5 | — | Sep 26, 2026 | Froxlor versions before 2.3.12 contain a credential disclosure vulnerability in the DirProtections.listing API command t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now