2026 CVE Vulnerabilities
64,766 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-88877 | CRITICAL | 9.8 | 0.4% | Sep 10, 2026 | Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, the Kubernetes ingress-nginx pr... |
| CVE-2026-88869 | CRITICAL | 9.3 | — | Sep 10, 2026 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in t... |
| CVE-2026-88864 | CRITICAL | 9.1 | — | Sep 10, 2026 | Capgo (capgo.app) fails to restrict direct write access to the public.sso_providers table exposed through Supabase Postg... |
| CVE-2026-38626 | CRITICAL | 9.8 | 0.2% | Sep 10, 2026 | Garlic-Hub v1.0.1 is vulnerable to SQL Injection in src/Modules/Items/Repositories/ItemsRepository.php. |
| CVE-2026-9163 | CRITICAL | 9.8 | — | Sep 10, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in GIS Informatics Gi... |
| CVE-2026-78082 | CRITICAL | 9.3 | 0.5% | Sep 10, 2026 | Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < ... |
| CVE-2026-8323 | CRITICAL | 9.3 | 0.3% | Sep 10, 2026 | URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Con... |
| CVE-2026-88285 | CRITICAL | 9.4 | 0.3% | Sep 10, 2026 | GeoVision GV-LPC2211 V1.13 exposes a network-accessible PTZ control service without authentication, allowing remote clie... |
| CVE-2026-88278 | CRITICAL | 9.8 | 0.3% | Sep 10, 2026 | GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a ca... |
| CVE-2026-59679 | CRITICAL | 9 | 0.4% | Sep 10, 2026 | fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) indexes the per-character encoding[] array using ... |
| CVE-2026-44950 | CRITICAL | 9 | 0.4% | Sep 10, 2026 | fs_read_glyphs() in the libXfont2 font-server client (src/fc/fserve.c) copies each glyph's bitmap into a single buffer. ... |
| CVE-2026-80352 | CRITICAL | 9.8 | 0.3% | Sep 10, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Camel K. A YAML injection vulnerabi... |
| CVE-2026-80351 | CRITICAL | 9.8 | 0.4% | Sep 10, 2026 | Improper neutralization of directives in dynamically evaluated code ('eval injection') vulnerability in Apache Camel K. ... |
| CVE-2026-7188 | CRITICAL | 9.8 | 0.3% | Sep 10, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Armiya Information... |
| CVE-2026-78361 | CRITICAL | 9.1 | 0.1% | Sep 10, 2026 | The zipMoney(Zip Co) Payments Plugin for WooCommerce WordPress plugin before 2.4.0 does not perform any authorisation ch... |
| CVE-2026-77770 | CRITICAL | 10 | 0.1% | Sep 10, 2026 | The miniOrange 2FA WordPress plugin before 6.3.1, miniOrange 2FA WordPress plugin before 19.3 does not require a valid... |
| CVE-2026-84939 | CRITICAL | 9.1 | 0.2% | Sep 10, 2026 | Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary m... |
| CVE-2026-67593 | CRITICAL | 9.1 | 0.5% | Sep 10, 2026 | A remote attacker can craft an Openwire RemoveSubscriptionInfo command to cause the deletion of a queue on the Artemis b... |
| CVE-2026-57967 | CRITICAL | 9.8 | 0.6% | Sep 10, 2026 | An unauthenticated remote attacker can craft a CORE protocol SESSION_REATTACH packet to steal an existing session and as... |
| CVE-2026-49364 | CRITICAL | 9.1 | 0.3% | Sep 10, 2026 | An unauthenticated network-adjacent attacker can leverage discovery to capture cluster administrative credentials during... |
| CVE-2026-19583 | CRITICAL | 9.9 | 0.6% | Sep 10, 2026 | Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell... |
| CVE-2026-18351 | CRITICAL | 9.8 | 0.8% | Sep 10, 2026 | The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all ver... |
| CVE-2026-87931 | CRITICAL | 9.6 | 0.4% | Sep 10, 2026 | A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Im... |
| CVE-2026-88069 | CRITICAL | 9.3 | 0.3% | Sep 9, 2026 | Pandora contains a path traversal vulnerability in its archive extraction worker. When processing a specially crafted ar... |
| CVE-2026-71805 | CRITICAL | 9.8 | 0.2% | Sep 9, 2026 | An arbitrary file upload and path traversal vulnerability exists in LZ-litchi 1.0.0. Unauthenticated remote attackers ca... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now