2026 CVE Vulnerabilities
64,779 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54644 | MEDIUM | 6.1 | 1.1% | Sep 17, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, the _errorMessage method in classes/gui.class.php uses strip... |
| CVE-2026-54643 | MEDIUM | 5.4 | 0.2% | Sep 17, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, the delete-note handler in admin/sources/orders.index.inc.ph... |
| CVE-2026-54642 | MEDIUM | 5.3 | 0.3% | Sep 17, 2026 | CubeCart is an ecommerce software solution. Prior to 6.7.5, the reset_id download-counter action and delete_card stored-... |
| CVE-2026-54633 | MEDIUM | 6.9 | 0.2% | Sep 17, 2026 | PoDoFo is a C++17 PDF manipulation library. From version 1.0.0 until 1.1.1, processing a crafted PDF with an Indexed col... |
| CVE-2026-54613 | MEDIUM | 5.4 | 0.2% | Sep 17, 2026 | Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.5... |
| CVE-2026-53556 | MEDIUM | 6 | 0.4% | Sep 17, 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /api/v1/dat... |
| CVE-2026-53555 | MEDIUM | 5.1 | 0.4% | Sep 17, 2026 | SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, an authenticated upl... |
| CVE-2026-50291 | MEDIUM | 5.5 | 0.2% | Sep 17, 2026 | OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / a... |
| CVE-2026-16750 | MEDIUM | 5.3 | — | Sep 17, 2026 | The Motors – Car Dealership & Classified Listings Plugin plugin for WordPress is vulnerable to unauthorized access of da... |
| CVE-2026-16582 | MEDIUM | 5.3 | — | Sep 17, 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized modificatio... |
| CVE-2026-14311 | MEDIUM | 5.4 | — | Sep 17, 2026 | The Booking for Appointments and Events Calendar – Amelia plugin for WordPress is vulnerable to unauthorized access and ... |
| CVE-2026-93395 | MEDIUM | 5.3 | 0.4% | Sep 17, 2026 | A missing lower-bound validation in the bson_new_from_buffer() function of libbson allows an integer underflow when proc... |
| CVE-2026-93387 | MEDIUM | 4.3 | — | Sep 17, 2026 | Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain cross-orig... |
| CVE-2026-93386 | MEDIUM | 5.4 | — | Sep 17, 2026 | UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging soci... |
| CVE-2026-93385 | MEDIUM | 6.5 | — | Sep 17, 2026 | Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to obtain sensitive informat... |
| CVE-2026-93383 | MEDIUM | 4.3 | — | Sep 17, 2026 | Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to leak cross-origin d... |
| CVE-2026-93379 | MEDIUM | 4.3 | 0.2% | Sep 17, 2026 | Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to bypass site isolatio... |
| CVE-2026-93376 | MEDIUM | 6.3 | 0.1% | Sep 17, 2026 | Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 allowed a local attacker leveraging social en... |
| CVE-2026-77281 | MEDIUM | 6.5 | 0.5% | Sep 17, 2026 | Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-depe... |
| CVE-2026-67071 | MEDIUM | 6.5 | — | Sep 17, 2026 | HCL DevOps Deploy / HCL Launch is susceptible to an information disclosure vulnerability when processing redacted proper... |
| CVE-2026-54918 | MEDIUM | 5.3 | 0.4% | Sep 17, 2026 | NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. In the a... |
| CVE-2026-54907 | MEDIUM | 5.3 | 0.2% | Sep 17, 2026 | Caddy Proxy Manager is a web interface for managing Caddy Server reverse proxies and certificates. Prior to 1.5.1, Caddy... |
| CVE-2026-54604 | MEDIUM | 5.3 | 0.3% | Sep 17, 2026 | OpenSlide is a C library for reading whole slide image files. Prior to 4.0.1, a behavior change in libtiff 4.7.1 causes ... |
| CVE-2026-54565 | MEDIUM | 4.7 | 0.2% | Sep 17, 2026 | rhwp is an HWP viewer and editor implemented in Rust and WebAssembly. Prior to rhwp 0.7.15 and rhwp Chrome and Firefox e... |
| CVE-2026-54521 | MEDIUM | 6.1 | 0.2% | Sep 17, 2026 | FairEmail is a fully featured, open source, privacy-friendly email app for Android. Prior to 1.2319, the ActivityAMP AMP... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now