2026 CVE Vulnerabilities
64,705 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-87074 | LOW | 3.7 | 0.2% | Sep 23, 2026 | The Forminator Forms WordPress plugin before 1.57.2.1 does not bind its saved-draft notification to the visitor who cre... |
| CVE-2026-87069 | LOW | 3.1 | 0.2% | Sep 23, 2026 | The Forminator Forms WordPress plugin before 1.57.2.1 does not perform a nonce, capability or ownership check before ru... |
| CVE-2026-84743 | LOW | 3.8 | 0.2% | Sep 23, 2026 | The Events Calendar WordPress plugin before 6.17.5 does not perform a per-object capability check on one family of its R... |
| CVE-2026-84742 | LOW | 2.7 | 0.2% | Sep 23, 2026 | The Events Calendar WordPress plugin before 6.17.5 does not check the capability required to publish content before crea... |
| CVE-2026-95958 | LOW | 3.3 | 0.2% | Sep 23, 2026 | A security flaw has been discovered in JusticeRage Manalyze 1.0.0. Impacted is the function PE::_parse_relocations of th... |
| CVE-2026-18173 | LOW | 3.7 | 0.4% | Sep 22, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to obtain sensitive informati... |
| CVE-2026-76909 | LOW | 2.1 | 0.5% | Sep 22, 2026 | Unleash is an open-source feature management platform. Prior to 8.0.3, the change-request approval email template at src... |
| CVE-2026-62364 | LOW | 2.3 | 0.1% | Sep 22, 2026 | wlc is a Weblate command-line client using Weblate's REST API. Prior to 2.0.1, automatically discovered configuration fr... |
| CVE-2026-95657 | LOW | 3.5 | 0.4% | Sep 22, 2026 | A vulnerability was determined in dgtlmoon Changedetection.io up to 0.55.8. This issue affects the function setCurrentSe... |
| CVE-2026-95818 | LOW | 3.6 | — | Sep 22, 2026 | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allo... |
| CVE-2026-92706 | LOW | 3.4 | 0.2% | Sep 22, 2026 | Dark Reader is an accessibility browser extension that makes web pages colors dark. Prior to 4.9.126, a website can caus... |
| CVE-2026-86698 | LOW | 2.3 | — | Sep 22, 2026 | Insufficient Session Expiration vulnerability in OAuth token issuance in hexpm hexpm allows a user whose organization me... |
| CVE-2026-81884 | LOW | 2.5 | 0.1% | Sep 22, 2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Mach-O LC_DATA_... |
| CVE-2026-81883 | LOW | 3.3 | 0.2% | Sep 22, 2026 | radare2 is a UNIX-like reverse engineering framework and command-line toolset. Prior to 6.2.0, radare2's Lua 5.3 bytecod... |
| CVE-2026-77637 | LOW | 3.8 | — | Sep 22, 2026 | Cloudreve is a self-hosted file management and sharing system. Prior to 4.18.0, tool.GET("wopi") and tool.POST("mail") i... |
| CVE-2026-95272 | LOW | 3.7 | — | Sep 22, 2026 | A vulnerability was found in dgtlmoon changedetection.io up to 0.60.7. This affects the function static_content of the f... |
| CVE-2026-95270 | LOW | 3.7 | — | Sep 22, 2026 | A flaw has been found in dgtlmoon changedetection.io up to 0.60.7. The affected element is the function check_password o... |
| CVE-2026-94426 | LOW | 3.5 | 0.3% | Sep 21, 2026 | A vulnerability was determined in xuxueli xxl-job up to 3.5.0. The impacted element is an unknown function of the file /... |
| CVE-2026-49449 | LOW | 2.5 | 0.1% | Sep 21, 2026 | Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. From 1.4.0 unt... |
| CVE-2026-85219 | LOW | 3.7 | 0.3% | Sep 21, 2026 | Denial-of-Service in Redis module in Thinkst Canary's OpenCanary 0.9.9 allows an unauthenticated remote attacker cause u... |
| CVE-2026-91165 | LOW | 2.4 | 0.4% | Sep 21, 2026 | Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.27.6, the response_mode=form_post SSO... |
| CVE-2026-63416 | LOW | 3.7 | 0.4% | Sep 21, 2026 | draw.io is a configurable diagramming and whiteboarding application. Prior to version 30.2.7, src/main/java/com/mxgraph/... |
| CVE-2026-84298 | LOW | 3.1 | 0.2% | Sep 21, 2026 | Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.95.3, th... |
| CVE-2026-77166 | LOW | 2.4 | 0.2% | Sep 21, 2026 | The emoji field in the page emoji update endpoint does not properly validate user input. By injecting long text and line... |
| CVE-2026-55870 | LOW | 2.3 | 0.4% | Sep 21, 2026 | GoCD is a continuous deliver server. Prior to 26.1.0, GoCD can return unmasked credentials that administrators stored in... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now