2026 CVE Vulnerabilities
65,654 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-62262 | CRITICAL | 9.1 | 0.3% | Sep 25, 2026 | Piwigo is a full featured open source photo gallery application for the web. In 17.0.0beta1 and earlier, when rating is ... |
| CVE-2026-54790 | MEDIUM | 6 | — | Sep 25, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo... |
| CVE-2026-50547 | HIGH | 7.5 | — | Sep 25, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo... |
| CVE-2026-49850 | HIGH | 7.5 | — | Sep 25, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo... |
| CVE-2026-44642 | HIGH | 8.1 | — | Sep 25, 2026 | Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, check_upgrade_access_right... |
| CVE-2026-42324 | HIGH | 7.2 | — | Sep 25, 2026 | Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/element_set_ranks.ph... |
| CVE-2026-42323 | HIGH | 7.2 | — | Sep 25, 2026 | Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/batch_manager.php ac... |
| CVE-2026-42322 | CRITICAL | 9.1 | — | Sep 25, 2026 | Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/themes_standard_page... |
| CVE-2026-39372 | MEDIUM | 4.9 | 0.3% | Sep 25, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo... |
| CVE-2026-39353 | CRITICAL | 9.1 | — | Sep 25, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2-rc-1,... |
| CVE-2026-33639 | HIGH | 7.2 | 0.4% | Sep 25, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. Prior to 1.7.2, Invo... |
| CVE-2026-100230 | MEDIUM | 5.3 | — | Sep 25, 2026 | Input Leap (aka input-leap) through 3.0.3, when the non-default --enable-drag-drop option is used on Windows or macOS, m... |
| CVE-2026-97866 | MEDIUM | 5.6 | — | Sep 25, 2026 | A weakness has been identified in Zhonglun CloudPOS 3.0. Affected by this vulnerability is an unknown functionality of t... |
| CVE-2026-96812 | HIGH | 8.8 | — | Sep 25, 2026 | Improper Exposure of Resource to Wrong Sphere in the host file helper (gofer) in Google gVisor prior to commit 573a9e73c... |
| CVE-2026-93306 | HIGH | 7.1 | 0.2% | Sep 25, 2026 | IBM Server Firmware FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.00 ... |
| CVE-2026-93030 | MEDIUM | 6.5 | — | Sep 25, 2026 | FTM 4.x ALL could allow a remote authenticated attacker to obtain sensitive information due to an XML external entity in... |
| CVE-2026-88389 | MEDIUM | 6.2 | — | Sep 25, 2026 | Espruino 2v29 (commit bffc6d0) contains a NULL pointer dereference vulnerability in jslGetRawString() in src/jslex.c. Cr... |
| CVE-2026-84882 | HIGH | 7.5 | — | Sep 25, 2026 | IBM Guardium Data Protection 12.2 is vulnerable to path traversal in the Universal Connector Oracle Wallet upload compon... |
| CVE-2026-84862 | HIGH | 7.2 | 0.4% | Sep 25, 2026 | IBM Guardium Data Protection 12.2 is vulnerable to insecure deserialization in the Quartz JDBC job store. An authenticat... |
| CVE-2026-60101 | — | — | — | Sep 25, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-60100 | — | — | — | Sep 25, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-60099 | — | — | — | Sep 25, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-60098 | — | — | — | Sep 25, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-60097 | — | — | — | Sep 25, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-60096 | — | — | — | Sep 25, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now