2026 CVE Vulnerabilities
64,779 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-14855 | MEDIUM | 6.4 | — | Sep 18, 2026 | The RT Mega Menu plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'css[left]' parameter in all ... |
| CVE-2026-93455 | MEDIUM | 6.5 | 0.3% | Sep 18, 2026 | django-page-cms through 2.0.13 fails to properly validate page permissions in admin helper views, allowing any staff acc... |
| CVE-2026-93314 | MEDIUM | 6.3 | 0.2% | Sep 18, 2026 | A vulnerability was determined in Freedesktop Poppler 26.07.0. This affects the function FoFiTrueType::mapCodeToGID of t... |
| CVE-2026-93313 | MEDIUM | 6.3 | — | Sep 18, 2026 | A vulnerability was found in Freedesktop Poppler 26.07.0. The impacted element is the function JBIG2Stream::readCodeTabl... |
| CVE-2026-82985 | MEDIUM | 6.5 | — | Sep 18, 2026 | The Photos app's filter-based "smart albums" build their file listing using the search configuration (photosSourceFolder... |
| CVE-2026-82982 | MEDIUM | 4.3 | — | Sep 18, 2026 | The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing ... |
| CVE-2026-82980 | MEDIUM | 6.3 | — | Sep 18, 2026 | Any authenticated user can lock or unlock files they do not own by targeting absolute WebDAV paths of other users. The D... |
| CVE-2026-77170 | MEDIUM | 4.3 | — | Sep 18, 2026 | The Deck config API allows authenticated users to set board-scoped configuration keys for arbitrary board IDs without va... |
| CVE-2026-77169 | MEDIUM | 6.5 | — | Sep 18, 2026 | A vulnerability in the team folders (formerly group folders) app when used in combination with the workspace app allowed... |
| CVE-2026-77164 | MEDIUM | 6.2 | — | Sep 18, 2026 | Circles' remote-instance signature verification fetches the attacker-supplied keyId URL before trust in the remote insta... |
| CVE-2026-93312 | MEDIUM | 4.3 | 0.3% | Sep 18, 2026 | A flaw has been found in Freedesktop Poppler 26.07.0. Impacted is the function JBIG2Stream::rewind of the file poppler/J... |
| CVE-2026-93311 | MEDIUM | 4.3 | 0.3% | Sep 18, 2026 | A vulnerability was detected in Freedesktop Poppler 26.07.0. This issue affects the function SampledFunction::SampledFun... |
| CVE-2026-93310 | MEDIUM | 5.3 | — | Sep 18, 2026 | A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. This affects an unknown part of the component VES Collect... |
| CVE-2026-93454 | MEDIUM | 5.4 | 0.2% | Sep 18, 2026 | Aureus ERP through 1.6.0 stores the Payment Term note field unsanitized and renders it as raw HTML in the Accounting plu... |
| CVE-2026-93451 | MEDIUM | 6.5 | 0.3% | Sep 18, 2026 | snappy-java through 1.1.10.8 contains a buffer overflow vulnerability in typed Snappy.uncompress*Array methods that allo... |
| CVE-2026-93309 | MEDIUM | 4.3 | 0.3% | Sep 18, 2026 | A vulnerability was determined in O-RAN-SC SMO OAM 2025-06-10. Affected by this issue is some unknown functionality of t... |
| CVE-2026-93308 | MEDIUM | 4.3 | — | Sep 18, 2026 | A vulnerability was found in O-RAN-SC SMO OAM 2025-06-10. Affected by this vulnerability is an unknown functionality of ... |
| CVE-2026-83946 | MEDIUM | 6.1 | 0.6% | Sep 18, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') in Azure Portal allows an unauthori... |
| CVE-2026-2585 | MEDIUM | 6.4 | 0.2% | Sep 18, 2026 | The Brizy – Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘rootAttributes’ para... |
| CVE-2026-18441 | MEDIUM | 4.3 | 0.2% | Sep 18, 2026 | The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable to I... |
| CVE-2026-55946 | MEDIUM | 5.9 | 0.7% | Sep 17, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unaut... |
| CVE-2026-93307 | MEDIUM | 4.3 | 0.3% | Sep 17, 2026 | A vulnerability has been found in O-RAN-SC SMO OAM 2025-06-10. Affected is an unknown function of the component VES Coll... |
| CVE-2026-73638 | MEDIUM | 6.2 | 0.2% | Sep 17, 2026 | Imager versions from 0.45_02 before 1.035 for Perl read outside the EXIF block via unchecked start offsets in tiff_load_... |
| CVE-2026-54648 | MEDIUM | 6.5 | 0.3% | Sep 17, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, the GDPR tools in admin/sources/customers.gdpr.inc.php rely ... |
| CVE-2026-54645 | MEDIUM | 4.8 | 1.1% | Sep 17, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/products.index.inc.php reads the description, ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now