2026 CVE Vulnerabilities
64,775 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-10832 | MEDIUM | 5.9 | 0.3% | Sep 18, 2026 | A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaus... |
| CVE-2026-93602 | MEDIUM | 4.4 | 0.2% | Sep 18, 2026 | rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain faulty CRL authority-matching logic that compares onl... |
| CVE-2026-93596 | MEDIUM | 4.3 | — | Sep 18, 2026 | ArcadeDB before 26.9.1 (com.arcadedb:arcadedb-engine <= 26.8.1) fails to bind the authenticated principal onto the Datab... |
| CVE-2026-93595 | MEDIUM | 6.5 | 0.3% | Sep 18, 2026 | ArcadeDB before 26.9.1 contains an access control bypass vulnerability in the query_database tool exposed through the AI... |
| CVE-2026-93504 | MEDIUM | 6.3 | 0.4% | Sep 18, 2026 | A vulnerability has been found in SveltyCMS 0.0.6. This affects an unknown part of the file src/routes/api/[...path]/+se... |
| CVE-2026-93018 | MEDIUM | 5.5 | 0.2% | Sep 18, 2026 | Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes pas... |
| CVE-2026-79294 | MEDIUM | 6.1 | 0.5% | Sep 18, 2026 | Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbi... |
| CVE-2026-62282 | MEDIUM | 6.5 | 0.3% | Sep 18, 2026 | OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and Slack int... |
| CVE-2026-93492 | MEDIUM | 5.3 | 0.4% | Sep 18, 2026 | A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames wi... |
| CVE-2026-93578 | MEDIUM | 5.9 | — | Sep 18, 2026 | A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSP... |
| CVE-2026-93561 | MEDIUM | 6.5 | 0.3% | Sep 18, 2026 | A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and ... |
| CVE-2026-92976 | MEDIUM | 5.1 | — | Sep 18, 2026 | A stored Cross-Site Scripting (XSS) vulnerability in the profile management functionality of T-Systems’ TAO 2.0 suite. A... |
| CVE-2026-90884 | MEDIUM | 5.4 | — | Sep 18, 2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' parameter in all v... |
| CVE-2026-15797 | MEDIUM | 6.4 | 0.4% | Sep 18, 2026 | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress ... |
| CVE-2026-56592 | MEDIUM | 6.5 | — | Sep 18, 2026 | HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate a... |
| CVE-2026-56590 | MEDIUM | 6.4 | — | Sep 18, 2026 | HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation c... |
| CVE-2026-4036 | MEDIUM | 6.5 | — | Sep 18, 2026 | An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Sharing API in ... |
| CVE-2026-40537 | MEDIUM | 4.3 | — | Sep 18, 2026 | A server-side request forgery (SSRF) vulnerability in PersonMail API in Synology DiskStation Manager (DSM) before 7.2.1-... |
| CVE-2026-40536 | MEDIUM | 4.3 | — | Sep 18, 2026 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Audio API in Synology... |
| CVE-2026-40535 | MEDIUM | 6.5 | — | Sep 18, 2026 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Desktop API in Synolo... |
| CVE-2026-40534 | MEDIUM | 5.4 | — | Sep 18, 2026 | An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Video API in Sy... |
| CVE-2026-40533 | MEDIUM | 5.3 | — | Sep 18, 2026 | An exposure of sensitive information through data queries vulnerability in Desktop API in Synology DiskStation Manager (... |
| CVE-2026-40532 | MEDIUM | 6.5 | — | Sep 18, 2026 | A direct request ('forced browsing') vulnerability in Wallpaper Path in Synology DiskStation Manager (DSM) before 7.2.1-... |
| CVE-2026-40531 | MEDIUM | 4.3 | — | Sep 18, 2026 | An integer overflow or wraparound vulnerability in File Operation in Synology DiskStation Manager (DSM) before 7.2.1-690... |
| CVE-2026-21848 | MEDIUM | 5 | — | Sep 18, 2026 | HCL BigFix Service Management is affected by a Security Misconfiguration vulnerability, which could allow an authenticat... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now