2026 CVE Vulnerabilities
65,524 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100869 | MEDIUM | 5.9 | — | Sep 27, 2026 | Sylius versions before 2.1.16 and 2.2.9 fail to restrict payment request actions in the Shop API endpoint, allowing cust... |
| CVE-2026-100868 | MEDIUM | 6.3 | — | Sep 27, 2026 | Penpot before 2.18.0 binds the MCP server plugin WebSocket bridge to all network interfaces without authentication in si... |
| CVE-2026-100867 | LOW | 3.3 | — | Sep 27, 2026 | spaceship-prompt through 4.22.5 fails to sanitize control characters from project manifest version fields before renderi... |
| CVE-2026-100866 | LOW | 3.3 | — | Sep 27, 2026 | onefetch through 2.28.1 writes repository information field values to the terminal without removing control characters, ... |
| CVE-2026-97165 | MEDIUM | 5.3 | — | Sep 27, 2026 | Joomla Extension - svenbluege.de - Reflected XSS and open redirect in Event Gallery extension < 6.5.0 - The “return” par... |
| CVE-2026-97164 | HIGH | 7 | 0.3% | Sep 27, 2026 | Joomla Extension - svenbluege.de - Authenticated arbitrary path deletion in `clear cache` task in Event Gallery extensio... |
| CVE-2026-100749 | MEDIUM | 5.1 | — | Sep 27, 2026 | Joomla Extension - svenbluege.de - CSRF in backend cleanup actions in Event Gallery extension < 6.5.0 - Only orphaned fi... |
| CVE-2026-100748 | MEDIUM | 6.9 | 0.2% | Sep 27, 2026 | Joomla Extension - svenbluege.de - CSRF in various cart actions in Event Gallery extension < 6.5.0 |
| CVE-2026-100747 | MEDIUM | 5.1 | — | Sep 27, 2026 | Joomla Extension - svenbluege.de - CSRF in image upload in Event Gallery extension < 6.5.0 - Due to lack of an CSRF toke... |
| CVE-2026-94417 | LOW | 2.3 | 0.2% | Sep 27, 2026 | When an application enables both OCSP and CRL revocation checking on one WOLFSSL_CTX or certificate manager, wolfSSL ski... |
| CVE-2026-93304 | MEDIUM | 6.3 | 0.2% | Sep 27, 2026 | A (D)TLS 1.2 client can accept a ChangeCipherSpec message before it has sent its ClientKeyExchange. No master secret has... |
| CVE-2026-93302 | HIGH | 8.3 | 0.3% | Sep 27, 2026 | MatchTrustedPeer ignores the public key used, leading to forged CA clones passing verification. Affected builds are any ... |
| CVE-2026-89136 | HIGH | 8.3 | 0.6% | Sep 27, 2026 | When using RPK (Raw Public Key), the client side of a TLS 1.2, 1.3 and DTLS 1.2 connection could accept an unsolicited s... |
| CVE-2026-89135 | MEDIUM | 6.3 | 0.2% | Sep 27, 2026 | A failed X509_verify_cert call permanently plants an unverified attacker CA in the shared CertManager, bypassing certifi... |
| CVE-2026-89134 | MEDIUM | 6.3 | 0.1% | Sep 27, 2026 | A certificate with no dNSName SAN but another SAN type present (e.g. registeredID or iPAddress) bypassed the Subject CN ... |
| CVE-2026-89133 | MEDIUM | 6.3 | 0.1% | Sep 27, 2026 | wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509 certificate validation logic where it fails to properly e... |
| CVE-2026-89102 | HIGH | 8.3 | 0.3% | Sep 27, 2026 | In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side implementation flaw in RFC 6961, multiple OCSP response s... |
| CVE-2026-15442 | LOW | 2.3 | — | Sep 27, 2026 | In all builds that make use of (D)TLS, including default builds, there is a series of conditional states during the TLS ... |
| CVE-2026-94419 | LOW | 2.3 | 0.1% | Sep 27, 2026 | Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not return a session object but a ClientSession reference of th... |
| CVE-2026-94418 | LOW | 2.3 | 0.1% | Sep 27, 2026 | Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs the certificate signature check separately from the parse t... |
| CVE-2026-100741 | CRITICAL | 9.8 | 1.7% | Sep 27, 2026 | Eval injection in the JScript event-script dispatcher in Progressive Robot Ltd's hMailServer, versions 6.0.0 through 6.3... |
| CVE-2026-97319 | MEDIUM | 6.8 | — | Sep 27, 2026 | The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.17.2 does not sanitize and escape a block attribu... |
| CVE-2026-97227 | MEDIUM | 5.9 | — | Sep 27, 2026 | The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not perform capability or ownership chec... |
| CVE-2026-96899 | MEDIUM | 6.8 | — | Sep 27, 2026 | The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value submitted through one o... |
| CVE-2026-96897 | MEDIUM | 5.3 | — | Sep 27, 2026 | The Optima Express IDX WordPress plugin before 8.7.6 does not perform any authorisation check on one of its AJAX actions... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now