2026 CVE Vulnerabilities
65,619 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-47679 | HIGH | 8.5 | — | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 10.0.0 until 10.0.26 and 11.0.8, any logged-in GLPI user c... |
| CVE-2026-45801 | MEDIUM | 5.3 | — | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated user witho... |
| CVE-2026-100306 | MEDIUM | 5.3 | — | Sep 25, 2026 | TDuck survey form through 6.0 fails to validate write passwords on submission endpoints, enforcing the check only on the... |
| CVE-2026-100305 | MEDIUM | 4.3 | — | Sep 25, 2026 | TDuck survey form through 6.0 fails to enforce form fill-in restrictions on the authenticated submission endpoint POST /... |
| CVE-2026-100304 | MEDIUM | 5.3 | 0.4% | Sep 25, 2026 | TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermission that fails open wh... |
| CVE-2026-100303 | MEDIUM | 5.4 | — | Sep 25, 2026 | TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes a... |
| CVE-2026-100192 | MEDIUM | 6.5 | 0.3% | Sep 25, 2026 | X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint withou... |
| CVE-2026-97886 | MEDIUM | 6.3 | 0.3% | Sep 25, 2026 | A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be... |
| CVE-2026-97885 | HIGH | 7.3 | — | Sep 25, 2026 | A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affecte... |
| CVE-2026-97884 | MEDIUM | 6.3 | — | Sep 25, 2026 | A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. ... |
| CVE-2026-97883 | HIGH | 7.3 | — | Sep 25, 2026 | A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db... |
| CVE-2026-97882 | HIGH | 7.3 | 0.5% | Sep 25, 2026 | A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be... |
| CVE-2026-93366 | MEDIUM | 5.4 | — | Sep 25, 2026 | Bludit CMS through 3.22.0 contains an authorization bypass vulnerability that allows authenticated users with the Author... |
| CVE-2026-91841 | HIGH | 7.8 | 0.2% | Sep 25, 2026 | A flaw was found in NetworkManager-vpnc, a VPN plugin for NetworkManager. A local unprivileged user can exploit this vul... |
| CVE-2026-91840 | HIGH | 7.8 | 0.2% | Sep 25, 2026 | A flaw was found in NetworkManager-vpnc. This vulnerability allows a local unprivileged user to escalate privileges to r... |
| CVE-2026-91839 | HIGH | 7.8 | 0.2% | Sep 25, 2026 | A flaw was found in NetworkManager-fortisslvpn, the FortiSSLVPN plugin for NetworkManager. The nm-fortisslvpn-service im... |
| CVE-2026-91838 | HIGH | 7.8 | — | Sep 25, 2026 | A flaw was found in NetworkManager-sstp, the SSTP VPN plugin for NetworkManager. A local unprivileged user can exploit t... |
| CVE-2026-84462 | HIGH | 8.6 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a security filter that protects Zamm... |
| CVE-2026-65828 | LOW | 2.3 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the legacy destroy_form action on At... |
| CVE-2026-61525 | HIGH | 8.8 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. In 7.0.2 and 7.1.0, zammad's session management for ... |
| CVE-2026-56735 | MEDIUM | 5.3 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, zammad's HTML sanitizer (H... |
| CVE-2026-56734 | MEDIUM | 5.3 | 0.4% | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, during federated authentication (OAu... |
| CVE-2026-56733 | HIGH | 8.7 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2 and 7.1.0, this issue concerns a lack... |
| CVE-2026-56732 | MEDIUM | 5.3 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.2, vulnerability in Zammad's HTML sanit... |
| CVE-2026-56731 | HIGH | 8.4 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.0.1, a low-privilege authenticated user m... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now