2026 CVE Vulnerabilities
64,729 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-81654 | LOW | 3.1 | 0.1% | Sep 20, 2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not check that a user holds its options ca... |
| CVE-2026-81652 | LOW | 2.7 | 0.1% | Sep 20, 2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the requesting user is ent... |
| CVE-2026-81651 | LOW | 3.1 | 0.1% | Sep 20, 2026 | The Photo Gallery, Sliders, Proofing and WordPress plugin before 4.5.0 does not verify that the user saving a gallery ... |
| CVE-2026-86551 | LOW | 3.3 | 0.2% | Sep 20, 2026 | The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address ... |
| CVE-2026-93989 | LOW | 3.1 | 0.2% | Sep 19, 2026 | vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in Sa... |
| CVE-2026-93956 | LOW | 3.5 | 0.2% | Sep 19, 2026 | A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by this issue is the function SearchEngine::buildHighl... |
| CVE-2026-93987 | LOW | 3.4 | 0.1% | Sep 19, 2026 | rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnerability in the `rclone serve docker` volume plugin.... |
| CVE-2026-93986 | LOW | 3.1 | 0.2% | Sep 19, 2026 | rclone before 1.75.1 fails to confine names from server and third-party listing responses to the listed directory, allow... |
| CVE-2026-93982 | LOW | 3.3 | 0.1% | Sep 19, 2026 | OpenPanel through commit bad75bdd writes Model Context Protocol authentication tokens from URL query parameters to plain... |
| CVE-2026-92420 | LOW | 3.8 | 0.2% | Sep 19, 2026 | The Hydra Booking — Appointment Scheduling & Booking Calendar WordPress plugin before 1.2.2 does not verify that a booki... |
| CVE-2026-92403 | LOW | 3.7 | 0.2% | Sep 19, 2026 | The Secure Custom Fields WordPress plugin before 6.9.4 does not properly verify that a front-end form submission corresp... |
| CVE-2026-93894 | LOW | 2.3 | 0.3% | Sep 18, 2026 | In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type ... |
| CVE-2026-63451 | LOW | 3.3 | 0.1% | Sep 18, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Fr... |
| CVE-2026-63450 | LOW | 3.7 | 0.2% | Sep 18, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2026-63449 | LOW | 3.7 | 0.2% | Sep 18, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Fr... |
| CVE-2026-57225 | LOW | 3.3 | 0.1% | Sep 18, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Fr... |
| CVE-2026-93841 | LOW | 3.7 | 0.2% | Sep 18, 2026 | vLLM through 0.29.0 contains a memory corruption vulnerability in the Triton _bincount_kernel where prompt token IDs ind... |
| CVE-2026-93840 | LOW | 3.7 | 0.2% | Sep 18, 2026 | vLLM before 0.29.0 validates allowed_token_ids against tokenizer length instead of model output logits width in Sampling... |
| CVE-2026-57226 | LOW | 3.7 | 0.6% | Sep 18, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2026-11545 | LOW | 3.7 | 0.3% | Sep 18, 2026 | IBM WebSphere Application Server 8.5 and 9.0 could allow a remote attacker to obtain sensitive information from the admi... |
| CVE-2026-93650 | LOW | 3.7 | — | Sep 18, 2026 | A vulnerability was determined in Saleor up to 3.20.118/3.21.54/3.22.47/3.23.14. This vulnerability affects the function... |
| CVE-2026-81181 | LOW | 3.7 | 0.2% | Sep 18, 2026 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for pro... |
| CVE-2026-81178 | LOW | 3.5 | — | Sep 18, 2026 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.55, an unauthenticated holder of a public no... |
| CVE-2026-91142 | LOW | 3.6 | — | Sep 18, 2026 | A flaw was found in Cockpit. An integer overflow vulnerability in the `do_lastlog()` function, specifically in the offse... |
| CVE-2026-85478 | LOW | 3.5 | 0.2% | Sep 18, 2026 | A CM2507 IP camera running firmware version HMT.CM2507 v251211.1507 exposes an interactive bootloader through a physical... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now