2026 CVE Vulnerabilities
64,772 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-77021 | MEDIUM | 5.3 | — | Sep 21, 2026 | Improper handling of highly compressed data (data amplification) in Checkmk <2.5.0p14, <2.4.0p37, <2.3.0p51 and 2.2.0 (E... |
| CVE-2026-94277 | MEDIUM | 6.3 | — | Sep 21, 2026 | MISP's galaxy matrix statistics view (app/View/Users/statistics_galaxymatrix.ctp) renders the galaxy name directly into ... |
| CVE-2026-91921 | MEDIUM | 5.1 | 0.4% | Sep 21, 2026 | Cross-Site Scripting (XSS) vulnerability due to inadequate input sanitisation in the client-side rendering engine of the... |
| CVE-2026-94152 | MEDIUM | 4.3 | 0.2% | Sep 21, 2026 | A security vulnerability has been detected in Omega Solution FBP Fulfillment by People 2025. This impacts an unknown fun... |
| CVE-2026-94151 | MEDIUM | 5.3 | 0.4% | Sep 21, 2026 | A weakness has been identified in Omega Solution HRM OS up to 20260717. This affects an unknown function of the file /ro... |
| CVE-2026-92400 | MEDIUM | 5.3 | 0.1% | Sep 21, 2026 | The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that an incoming payment not... |
| CVE-2026-85113 | MEDIUM | 6.5 | 0.2% | Sep 21, 2026 | The GiveWP WordPress plugin before 4.16.9 does not remove shortcode delimiters from donor-supplied values before renderi... |
| CVE-2026-85010 | MEDIUM | 5.3 | 0.2% | Sep 21, 2026 | The RestroPress WordPress plugin before 3.4.6 does not validate a client-supplied item add-on price on the server side w... |
| CVE-2026-94149 | MEDIUM | 4.3 | — | Sep 21, 2026 | A vulnerability was identified in Omega Solution HRM OS up to 20260717. The affected element is an unknown function of t... |
| CVE-2026-94148 | MEDIUM | 5.3 | 0.3% | Sep 21, 2026 | A vulnerability was determined in ScadaBR up to 1.1. Impacted is the function EmportDwr.createExportJSON of the file /Sc... |
| CVE-2026-94215 | MEDIUM | 5.5 | 0.2% | Sep 21, 2026 | A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The issue oc... |
| CVE-2026-94213 | MEDIUM | 4.9 | 0.2% | Sep 21, 2026 | A flaw was found in the Authorization Services component of Keycloak, an open-source identity and access management solu... |
| CVE-2026-94138 | MEDIUM | 6.6 | 2.1% | Sep 21, 2026 | A security flaw has been discovered in Chengdu Feiyuxing Technology Feiyu Star Router B-MB5E202-210322-r11656. This impa... |
| CVE-2026-94185 | MEDIUM | 5.5 | 0.3% | Sep 21, 2026 | nvm resolves a requested version or alias by treating it as a filename under $NVM_DIR/alias. Before 0.40.8, nvm_alias() ... |
| CVE-2026-94103 | MEDIUM | 4.7 | 0.2% | Sep 21, 2026 | A vulnerability has been found in RooCMS up to 1.2.2/1.3.4/1.4RC2. This impacts the function eval of the file roocms/sit... |
| CVE-2026-94102 | MEDIUM | 4.3 | 0.3% | Sep 21, 2026 | A flaw has been found in WuzhiCMS up to 4.1.0. This affects an unknown function of the file /index.php?m=member&v=Login ... |
| CVE-2026-94094 | MEDIUM | 4.3 | 0.3% | Sep 20, 2026 | A flaw has been found in OpenClaw up to 2026.9.5. Affected is the function createCanvasHostHandler of the file extension... |
| CVE-2026-94093 | MEDIUM | 6.3 | 0.3% | Sep 20, 2026 | A security vulnerability has been detected in DLR-RM stable-baselines3 up to 2.9.0. This affects the function PPO.load/l... |
| CVE-2026-94092 | MEDIUM | 5.5 | 0.2% | Sep 20, 2026 | A vulnerability was detected in dmlc dgl up to 2.1.0. This impacts the function load_info/_read_torch_data of the file u... |
| CVE-2026-94091 | MEDIUM | 5.5 | — | Sep 20, 2026 | A weakness has been identified in piskvorky gensim up to 4.4.0. The impacted element is the function Load of the file ge... |
| CVE-2026-94090 | MEDIUM | 6.3 | 0.3% | Sep 20, 2026 | A security flaw has been discovered in JusticeRage Manalyze 1.0.0. The affected element is the function PE::_parse_debug... |
| CVE-2026-94051 | MEDIUM | 6.3 | 0.2% | Sep 20, 2026 | A vulnerability was found in 0717376 cowork_bench up to d943e75bc0fc8e3b27141979300cd8cbcd1e890d. Affected by this vulne... |
| CVE-2026-94050 | MEDIUM | 4.3 | 0.2% | Sep 20, 2026 | A vulnerability has been found in D-Link DIR-X1860Z up to 1.0.2.220120.165402. Affected is the function routerd.wificfg_... |
| CVE-2026-94049 | MEDIUM | 4.3 | — | Sep 20, 2026 | A flaw has been found in 06ketan slideshot up to 4.4.0. This impacts the function render_slides of the file packages/cli... |
| CVE-2026-94048 | MEDIUM | 6.6 | 0.2% | Sep 20, 2026 | A vulnerability was detected in CodeAstro QR Code Attendance Management System 1.0. This affects the function Save of th... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now