2026 CVE Vulnerabilities
65,619 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-100380 | MEDIUM | 5.3 | — | Sep 25, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2026-100379 | MEDIUM | 5.3 | — | Sep 25, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App a... |
| CVE-2026-100378 | MEDIUM | 5.3 | — | Sep 25, 2026 | Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - Translate Extension allows Accessing Functionali... |
| CVE-2026-100377 | MEDIUM | 6.9 | — | Sep 25, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - WikiLambda ... |
| CVE-2026-100376 | MEDIUM | 4.8 | — | Sep 25, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2026-100369 | HIGH | 8.4 | 0.4% | Sep 25, 2026 | CliInvoke and its formerly named `AlastairLundy.CliInvoke` package are .NET libraries for invoking command-line programs... |
| CVE-2026-96878 | MEDIUM | 6.9 | — | Sep 25, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo ... |
| CVE-2026-96877 | MEDIUM | 6.9 | — | Sep 25, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo ... |
| CVE-2026-96876 | MEDIUM | 6.9 | — | Sep 25, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo ... |
| CVE-2026-96875 | MEDIUM | 6.9 | — | Sep 25, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo ... |
| CVE-2026-93682 | MEDIUM | 5.8 | — | Sep 25, 2026 | When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redi... |
| CVE-2026-5267 | HIGH | 7.5 | — | Sep 25, 2026 | Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API tha... |
| CVE-2026-57861 | — | — | — | Sep 25, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-53990 | — | — | — | Sep 25, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-100373 | MEDIUM | 4.1 | — | Sep 25, 2026 | OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function... |
| CVE-2026-100372 | HIGH | 7.2 | 1.1% | Sep 25, 2026 | ClipBucket v5 before 5.5.3-#197 contains a path traversal vulnerability in the admin template editor that allows authent... |
| CVE-2026-100368 | HIGH | 8.4 | — | Sep 25, 2026 | CliInvoke is a .NET library for invoking command-line programs, and its `CliInvoke.Specializations` packages provide spe... |
| CVE-2026-100310 | HIGH | 7 | — | Sep 25, 2026 | GNU libextractor before 1.16 loads plugins from an untrusted search path specified by the LIBEXTRACTOR_PREFIX environmen... |
| CVE-2026-100208 | HIGH | 7.5 | — | Sep 25, 2026 | Integer overflow or wraparound in Microsoft Office Outlook allows an unauthorized attacker to execute code over a networ... |
| CVE-2026-97897 | LOW | 3.5 | 0.2% | Sep 25, 2026 | A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the... |
| CVE-2026-97896 | LOW | 3.5 | — | Sep 25, 2026 | A vulnerability was identified in krayin laravel-crm up to 2.2.5. This vulnerability affects the function ConfigurationF... |
| CVE-2026-97895 | MEDIUM | 6.3 | — | Sep 25, 2026 | A vulnerability was determined in krayin laravel-crm up to 2.2.5. This affects an unknown part of the file packages/Webk... |
| CVE-2026-97064 | CRITICAL | 9.1 | — | Sep 25, 2026 | X-SpringBoot through 6.0 ships with a hardcoded static master login verification code 172839 enabled by default in the d... |
| CVE-2026-97063 | CRITICAL | 9.1 | — | Sep 25, 2026 | X-SpringBoot through 6.0 returns login verification codes in HTTP responses from unauthenticated endpoints GET /sys/mobi... |
| CVE-2026-97060 | HIGH | 7.2 | 0.3% | Sep 25, 2026 | X-SpringBoot through 6.0 lacks object-level authorization in user management endpoints, allowing sub-administrators to m... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now