2026 CVE Vulnerabilities
64,779 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86522 | MEDIUM | 6.3 | — | Sep 17, 2026 | Improper Output Neutralization for Logs vulnerability in team-alembic AshAuthentication allows an unauthenticated attack... |
| CVE-2026-81829 | MEDIUM | 5.3 | 0.4% | Sep 17, 2026 | A flaw was found in SmallRye JWT's AwsAlbKeyResolver, which is used by applications to verify JSON Web Tokens signed by ... |
| CVE-2026-81453 | MEDIUM | 6.5 | — | Sep 17, 2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Limitation of a Pathname to a Res... |
| CVE-2026-81443 | MEDIUM | 6.4 | 0.2% | Sep 17, 2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Server-Side Request Forgery (SSRF) vulnerab... |
| CVE-2026-80355 | MEDIUM | 5.4 | — | Sep 17, 2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Cross-Site Request Forgery (CSRF) vulnerabi... |
| CVE-2026-78528 | MEDIUM | 5.3 | 0.2% | Sep 17, 2026 | Unauthenticated Broken Access Control in BerqWP <= 4.1.15 versions. |
| CVE-2026-78294 | MEDIUM | 6.5 | 0.2% | Sep 17, 2026 | Contributor Cross Site Scripting (XSS) in Geo Mashup <= 1.13.21 versions. |
| CVE-2026-78223 | MEDIUM | 6.9 | — | Sep 17, 2026 | Improper Verification of Cryptographic Signature vulnerability in team-alembic AshAuthentication allows a caller of the ... |
| CVE-2026-74017 | MEDIUM | 5.3 | — | Sep 17, 2026 | Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions. |
| CVE-2026-74005 | MEDIUM | 5.4 | — | Sep 17, 2026 | Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions. |
| CVE-2026-74002 | MEDIUM | 5.3 | 0.2% | Sep 17, 2026 | Unauthenticated Broken Access Control in Booking Calendar <= 11.7 versions. |
| CVE-2026-74000 | MEDIUM | 5.3 | — | Sep 17, 2026 | Contributor Broken Access Control in Simple Membership <= 4.8.2 versions. |
| CVE-2026-73999 | MEDIUM | 5.4 | 0.2% | Sep 17, 2026 | Contributor Insecure Direct Object References (IDOR) in Cooked <= 1.16.0 versions. |
| CVE-2026-71568 | MEDIUM | 5.3 | — | Sep 17, 2026 | In BMCtest, Ironic is started without authentication and TLS for the duration of the test. Exploiting the problem requir... |
| CVE-2026-66676 | MEDIUM | 5.3 | — | Sep 17, 2026 | Unauthenticated Broken Access Control in Easy Invoice <= 2.3.8 versions. |
| CVE-2026-66617 | MEDIUM | 6.5 | 0.2% | Sep 17, 2026 | Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions. |
| CVE-2026-66608 | MEDIUM | 6.4 | — | Sep 17, 2026 | Contributor Server Side Request Forgery (SSRF) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= ... |
| CVE-2026-66579 | MEDIUM | 6.5 | 0.2% | Sep 17, 2026 | Contributor Cross Site Scripting (XSS) in JetElements For Elementor <= 2.9.2.1 versions. |
| CVE-2026-66578 | MEDIUM | 6.5 | — | Sep 17, 2026 | Contributor Cross Site Scripting (XSS) in PropertyHive <= 2.2.6 versions. |
| CVE-2026-66577 | MEDIUM | 6.5 | 0.2% | Sep 17, 2026 | Contributor Cross Site Scripting (XSS) in JetSearch <= 3.6.3 versions. |
| CVE-2026-66576 | MEDIUM | 6.5 | — | Sep 17, 2026 | Contributor Cross Site Scripting (XSS) in JetBlocks For Elementor <= 1.5.2 versions. |
| CVE-2026-66575 | MEDIUM | 5.3 | — | Sep 17, 2026 | Unauthenticated Insecure Direct Object References (IDOR) in King Addons for Elementor <= 51.1.81 versions. |
| CVE-2026-66574 | MEDIUM | 6.5 | 0.2% | Sep 17, 2026 | Contributor Cross Site Scripting (XSS) in Element Pack Elementor Addons <= 8.8.3 versions. |
| CVE-2026-66573 | MEDIUM | 6.5 | — | Sep 17, 2026 | Contributor Cross Site Scripting (XSS) in JetTabs <= 2.3.3.1 versions. |
| CVE-2026-66572 | MEDIUM | 6.5 | 0.2% | Sep 17, 2026 | Contributor Cross Site Scripting (XSS) in JetBlog <= 2.4.10 versions. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now