2026 CVE Vulnerabilities
64,775 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85688 | CRITICAL | 9.8 | 2.6% | Sep 4, 2026 | TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-c... |
| CVE-2026-85684 | CRITICAL | 9.1 | 0.7% | Sep 4, 2026 | marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitiz... |
| CVE-2026-85672 | CRITICAL | 9.8 | 1.5% | Sep 4, 2026 | zerox 1.1.20 contains an OS command injection vulnerability in the file download mechanism where the temporary file exte... |
| CVE-2026-85667 | CRITICAL | 9.1 | 0.4% | Sep 4, 2026 | xiaobei through 5.5.2 fails to implement authentication or signature validation on webhook endpoints, allowing unauthent... |
| CVE-2026-85663 | CRITICAL | 9.8 | 0.5% | Sep 4, 2026 | Aim 3.29.1 remote tracking server fails to authenticate requests and dispatches arbitrary methods through getattr withou... |
| CVE-2026-85661 | CRITICAL | 9.8 | 0.4% | Sep 4, 2026 | excel-mcp-server 0.1.8 fails to enforce path confinement in stdio mode when EXCEL_FILES_PATH is unset, allowing attacker... |
| CVE-2026-85597 | CRITICAL | 9.1 | 0.2% | Sep 4, 2026 | Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows un... |
| CVE-2026-85596 | CRITICAL | 9.8 | 0.2% | Sep 4, 2026 | Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider. The... |
| CVE-2026-85595 | CRITICAL | 9.8 | 0.4% | Sep 4, 2026 | Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in t... |
| CVE-2026-85594 | CRITICAL | 9.8 | 0.2% | Sep 4, 2026 | Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/s... |
| CVE-2026-85184 | CRITICAL | 9.1 | 0.3% | Sep 4, 2026 | @fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to run path-scoped middleware by matching against the ... |
| CVE-2026-82923 | CRITICAL | 9.8 | 0.6% | Sep 4, 2026 | The AI Website Builder WordPress plugin (GitHub build) 1.0.0 does not perform any authorisation or nonce check on its RE... |
| CVE-2026-85085 | CRITICAL | 9.6 | 0.2% | Sep 4, 2026 | The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who... |
| CVE-2026-80181 | CRITICAL | 9.1 | 0.2% | Sep 4, 2026 | Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: thr... |
| CVE-2026-70403 | CRITICAL | 9.3 | 0.3% | Sep 4, 2026 | XING CPTrans-ME-X contains a Use of Hard-coded Password (CWE-259). Anyone with the knowledge of the credential may log i... |
| CVE-2026-69657 | CRITICAL | 9.3 | 0.3% | Sep 4, 2026 | XING CPTrans-ME-X contains a Use of Default Password (CWE-1393). Anyone with the knowledge of the credential may log in ... |
| CVE-2026-62928 | CRITICAL | 9.3 | 1.2% | Sep 4, 2026 | XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected. |
| CVE-2026-15354 | CRITICAL | 9.8 | 0.3% | Sep 4, 2026 | The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.... |
| CVE-2026-85509 | CRITICAL | 9.8 | 0.4% | Sep 4, 2026 | FreeIPMI before 1.6.19 has a stack-based buffer overflow in _read_fru_data in libfreeipmi/fru/ipmi-fru.c when a BMC retu... |
| CVE-2026-85508 | CRITICAL | 9.8 | 0.4% | Sep 4, 2026 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info in ipmi-o... |
| CVE-2026-85507 | CRITICAL | 9.8 | 0.4% | Sep 4, 2026 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _output_dell_system_info_cmc_info in ipmi-oem/ip... |
| CVE-2026-85506 | CRITICAL | 9.8 | 0.4% | Sep 4, 2026 | ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipm... |
| CVE-2026-85504 | CRITICAL | 9.8 | 0.4% | Sep 4, 2026 | FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi... |
| CVE-2026-11613 | CRITICAL | 9.8 | 0.5% | Sep 4, 2026 | The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.... |
| CVE-2026-85148 | CRITICAL | 9.8 | 0.4% | Sep 4, 2026 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now