2026 CVE Vulnerabilities
64,775 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85043 | CRITICAL | 9.1 | 0.3% | Sep 3, 2026 | Incomplete cleanup in Network in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to bypass system access ... |
| CVE-2026-85042 | CRITICAL | 9.6 | 0.3% | Sep 3, 2026 | Use after free in DevTools in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code o... |
| CVE-2026-85394 | CRITICAL | 9.1 | 0.4% | Sep 3, 2026 | python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded publi... |
| CVE-2026-85391 | CRITICAL | 9.8 | 0.3% | Sep 3, 2026 | Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attac... |
| CVE-2026-82526 | CRITICAL | 9.8 | 0.4% | Sep 3, 2026 | R2R through 3.6.6 contains a stacked SQL injection vulnerability that allows unauthenticated attackers to execute arbitr... |
| CVE-2026-58400 | CRITICAL | 9.1 | 1.2% | Sep 3, 2026 | GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the S... |
| CVE-2026-84834 | CRITICAL | 9.8 | 0.3% | Sep 3, 2026 | Unauthenticated PHP Object Injection in JobSearch <= 3.2.0 versions. |
| CVE-2026-84814 | CRITICAL | 9.8 | — | Sep 3, 2026 | Subscriber Privilege Escalation in Bricksforge <= 3.1.8.8 versions. |
| CVE-2026-84813 | CRITICAL | 9.3 | — | Sep 3, 2026 | Unauthenticated SQL Injection in GeoDirectory <= 2.8.174 versions. |
| CVE-2026-84768 | CRITICAL | 9.3 | — | Sep 3, 2026 | Unauthenticated SQL Injection in VikAppointments Services Booking Calendar <= 1.2.20 versions. |
| CVE-2026-84753 | CRITICAL | 9.8 | 0.3% | Sep 3, 2026 | Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions. |
| CVE-2026-84238 | CRITICAL | 9.8 | 0.3% | Sep 3, 2026 | Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions. |
| CVE-2026-85221 | CRITICAL | 9.1 | 0.1% | Sep 3, 2026 | MISP contains an improper TLS certificate validation vulnerability in CurlClient. The CurlClient::$verifyPeer property w... |
| CVE-2026-85216 | CRITICAL | 9.8 | 0.5% | Sep 3, 2026 | MISP contains an authentication bypass vulnerability in its LDAP and LinOTP authentication components due to insufficien... |
| CVE-2026-85183 | CRITICAL | 9.3 | 0.2% | Sep 3, 2026 | Taipy configures its socket.io server with wildcard CORS origin and credential flag enabled, allowing any web page to es... |
| CVE-2026-85181 | CRITICAL | 9.8 | 0.4% | Sep 3, 2026 | CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attac... |
| CVE-2026-85109 | CRITICAL | 9.8 | — | Sep 3, 2026 | A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/f... |
| CVE-2026-82180 | CRITICAL | 9.5 | — | Sep 3, 2026 | In Eclipse Arrowhead versions from 5.0.0 to 5.2.1 when the MQTT API is enabled with the certificate authentication polic... |
| CVE-2026-85165 | CRITICAL | 9.9 | 0.3% | Sep 3, 2026 | n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed... |
| CVE-2026-85154 | CRITICAL | 9.8 | 0.3% | Sep 3, 2026 | WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-r... |
| CVE-2026-85031 | CRITICAL | 9.9 | 0.6% | Sep 3, 2026 | A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cste... |
| CVE-2026-80726 | CRITICAL | 9.3 | 0.2% | Sep 3, 2026 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: WARN and clear role.invalid when crea... |
| CVE-2026-78080 | CRITICAL | 9.3 | — | Sep 3, 2026 | Joomla Extension - feenders.de - Unauthenticated SQL injection in JooDatabase Lite < 5.1.0 - The cid parameter is used i... |
| CVE-2026-78069 | CRITICAL | 9.5 | — | Sep 3, 2026 | Joomla Extension - j2commerce.com - Missing authorization on Apps controller delegation chain in J2Store 1.0.0-3.3.21, 4... |
| CVE-2026-76178 | CRITICAL | 9.2 | — | Sep 3, 2026 | A stored Cross-Site Scripting (XSS) vulnerability in the notification template functionality of the endpoint /ocsreports... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now