2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-92616 | MEDIUM | 6.8 | — | Sep 16, 2026 | FileRise before version 3.28.0 contains a privilege escalation vulnerability that allows authenticated low-privilege att... |
| CVE-2026-92570 | MEDIUM | 6.5 | 0.3% | Sep 16, 2026 | reNgine through 2.2.0 contains an authorization bypass vulnerability in the GetFileContents API endpoint that allows any... |
| CVE-2026-92569 | MEDIUM | 4.3 | 0.3% | Sep 16, 2026 | Hippo4j through 1.5.0 contains a server-side request forgery vulnerability in four ThreadPoolController endpoints that f... |
| CVE-2026-92568 | MEDIUM | 5.4 | 0.3% | Sep 16, 2026 | MLRun through 1.11.0 contains a server-side request forgery vulnerability in the WebhookNotification handler that allows... |
| CVE-2026-92567 | MEDIUM | 6.5 | 0.4% | Sep 16, 2026 | TDuck survey form through version 5.0 contains an authorization bypass vulnerability in the POST /user/form/data/update ... |
| CVE-2026-92565 | MEDIUM | 5.3 | 0.4% | Sep 16, 2026 | Rallly before 4.15.0 contains an information disclosure vulnerability in the polls.get tRPC procedure that returns sched... |
| CVE-2026-92383 | MEDIUM | 4.3 | — | Sep 16, 2026 | A security vulnerability has been detected in PbootCMS up to 3.2.24. This vulnerability affects the function UserControl... |
| CVE-2026-89031 | MEDIUM | 5.4 | 0.3% | Sep 16, 2026 | Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to modify the scheduled post records o... |
| CVE-2026-88976 | MEDIUM | 6.1 | — | Sep 16, 2026 | Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.11, and in the discontinued 54.0.0-beta.0 through 54.0.... |
| CVE-2026-84859 | MEDIUM | 6.5 | — | Sep 16, 2026 | ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Blind SQL Injection The /api/events/search e... |
| CVE-2026-77401 | MEDIUM | 6.8 | — | Sep 16, 2026 | Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untruste... |
| CVE-2026-77119 | MEDIUM | 5.9 | — | Sep 16, 2026 | A validly signed NSEC3 from an unrelated sibling zone may be accepted as an insecurity proof, downgrading a secure deleg... |
| CVE-2026-75029 | MEDIUM | 5.3 | — | Sep 16, 2026 | In a query response, an attacker may send `named` multiple copies of a record that should only exist once (such as an SO... |
| CVE-2026-61709 | MEDIUM | 5.3 | 0.4% | Sep 16, 2026 | OpenFGA is an authorization and permission engine built for developers. Prior to 1.18.1, the ListUsers API could return ... |
| CVE-2026-19668 | MEDIUM | 5.3 | — | Sep 16, 2026 | A BIND recursive resolver may experience excessive resource consumption if it encounters large numbers of a particular k... |
| CVE-2026-19033 | MEDIUM | 6.5 | — | Sep 16, 2026 | For a secondary zone with transfers restricted by TSIG, `named` may start to serve the data provided in a zone transfer ... |
| CVE-2026-92468 | MEDIUM | 6.5 | — | Sep 16, 2026 | zlt2000 microservices-platform through 6.0.0 contains an authorization bypass vulnerability in the search-center service... |
| CVE-2026-92365 | MEDIUM | 4.3 | 0.4% | Sep 16, 2026 | A vulnerability was found in vllm-project vllm up to 0.29.0. Affected by this issue is some unknown functionality of the... |
| CVE-2026-92364 | MEDIUM | 6.3 | — | Sep 16, 2026 | A vulnerability has been found in itsourcecode Leave Management System 1.0. Affected by this vulnerability is an unknown... |
| CVE-2026-92363 | MEDIUM | 4.3 | — | Sep 16, 2026 | A flaw has been found in ag-ui-protocol ag-ui 1.0. Affected is an unknown function of the file src/stream/sse_parser.cpp... |
| CVE-2026-92141 | MEDIUM | 4.3 | — | Sep 16, 2026 | Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict the redirect URL after login, allowing attack... |
| CVE-2026-92140 | MEDIUM | 6.8 | — | Sep 16, 2026 | Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in ... |
| CVE-2026-92139 | MEDIUM | 6.5 | — | Sep 16, 2026 | Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts values provided in the webhook payload, includin... |
| CVE-2026-92138 | MEDIUM | 4.2 | — | Sep 16, 2026 | The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plugin 6.0.1 and earlier reads the `oauth_callb... |
| CVE-2026-92133 | MEDIUM | 5.4 | — | Sep 16, 2026 | Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API client built for alternative GitLab API to... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now