2026 CVE Vulnerabilities
65,524 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100744 | HIGH | 7.3 | — | Sep 27, 2026 | A flaw has been found in coollabsio Coolify up to 4.1.2. The affected element is an unknown function of the file app/Htt... |
| CVE-2026-100725 | MEDIUM | 6.5 | — | Sep 27, 2026 | http4k (Maven artifact org.http4k:http4k-core) before 6.48.0.0, 5.42.0.0, and 4.51.0.0 ships a BasicCookieStorage (clien... |
| CVE-2026-100724 | MEDIUM | 5.4 | — | Sep 27, 2026 | http4k (Maven package org.http4k:http4k-core) before 6.49.0.0, 5.42.0.0 and 4.51.0.0 uses substring (Contains) matching ... |
| CVE-2026-100723 | HIGH | 7.5 | — | Sep 27, 2026 | vm2 before 3.12.2 does not apply its Buffer backing-store ownership invariant (byteOffset === 0 and buffer.byteLength ==... |
| CVE-2026-100722 | MEDIUM | 6.8 | 0.3% | Sep 27, 2026 | vm2 before 3.12.2 does not apply host-side Promise rejection handling in the sandbox-to-host construct trap. In BaseHand... |
| CVE-2026-100721 | CRITICAL | 9 | — | Sep 27, 2026 | vm2 before 3.12.2 contains an authorization bypass in the NodeVM external-module resolver. When an embedder configures `... |
| CVE-2026-100740 | CRITICAL | 9.9 | — | Sep 27, 2026 | A vulnerability was detected in D-Link DIR-895L A1_102b07. Impacted is the function tunnel_set_params of the file tunnel... |
| CVE-2026-100739 | HIGH | 7.3 | — | Sep 26, 2026 | A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. ... |
| CVE-2026-94408 | MEDIUM | 4.9 | — | Sep 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-... |
| CVE-2026-94400 | MEDIUM | 6.5 | — | Sep 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in Kibana can lead denial of service via Excessive Allocation (CAPEC-130) |
| CVE-2026-94399 | MEDIUM | 6.5 | — | Sep 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-... |
| CVE-2026-94398 | MEDIUM | 6.5 | — | Sep 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-... |
| CVE-2026-94397 | MEDIUM | 6.5 | — | Sep 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-... |
| CVE-2026-94396 | MEDIUM | 6.5 | 0.4% | Sep 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead denial of service via Excessive Allocation (CAPEC-... |
| CVE-2026-82300 | MEDIUM | 6.5 | 0.4% | Sep 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP... |
| CVE-2026-82294 | MEDIUM | 6.5 | 0.4% | Sep 26, 2026 | Uncontrolled Resource Consumption (CWE-400) in Elasticsearch can lead to denial of service via Excessive Allocation (CAP... |
| CVE-2026-78582 | MEDIUM | 6.5 | — | Sep 26, 2026 | Missing Authorization (CWE-862) in Kibana can lead to unauthorized deletion of data via Exploiting Incorrectly Configure... |
| CVE-2026-72668 | HIGH | 7.3 | — | Sep 26, 2026 | Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana Agent Builder can lead to privilege escalation.... |
| CVE-2026-72662 | MEDIUM | 6.3 | — | Sep 26, 2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized disclosure, modification, ... |
| CVE-2026-82901 | CRITICAL | 9.8 | — | Sep 26, 2026 | The Ultra Addons for Contact Form 7 plugin for WordPress is vulnerable to Arbitrary File Upload due to insufficient file... |
| CVE-2026-85984 | CRITICAL | 9.8 | — | Sep 26, 2026 | The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass... |
| CVE-2026-77203 | HIGH | 8.8 | — | Sep 26, 2026 | The Groups – Memberships and Access Control plugin for WordPress is vulnerable to Privilege Escalation in all versions u... |
| CVE-2026-97163 | CRITICAL | 10 | — | Sep 26, 2026 | Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 |
| CVE-2026-97162 | HIGH | 8.3 | — | Sep 26, 2026 | Joomla Extension - lomart.fr - Various SQL injection vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29 |
| CVE-2026-97161 | CRITICAL | 9.2 | — | Sep 26, 2026 | Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now