2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-92916 | HIGH | 7.5 | — | Sep 17, 2026 | Grav is a flat-file CMS. In Grav 1.7.0 through 1.7.53.2 and 2.0.0 through 2.0.21, when the debugger is enabled (system.d... |
| CVE-2026-92915 | HIGH | 7.3 | 0.3% | Sep 17, 2026 | WWBN AVideo through commit e01e41ecc (no patched version available) contains a broken access control flaw in objects/use... |
| CVE-2026-92914 | HIGH | 8.1 | 0.3% | Sep 17, 2026 | AVideo LoginControl contains an authentication bypass vulnerability in the PGP second factor verification that compares ... |
| CVE-2026-92913 | HIGH | 7.4 | 0.5% | Sep 17, 2026 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 uses a cryptographically weak pseudo-random number genera... |
| CVE-2026-81480 | HIGH | 7.2 | — | Sep 17, 2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Stack-based Buffer Overflow vulnerability. ... |
| CVE-2026-81478 | HIGH | 8.1 | — | Sep 17, 2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Cryptographic Key vulnera... |
| CVE-2026-81477 | HIGH | 7.2 | — | Sep 17, 2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A... |
| CVE-2026-81476 | HIGH | 8.1 | — | Sep 17, 2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Improper Neutralization of Special Element... |
| CVE-2026-81475 | HIGH | 8.1 | — | Sep 17, 2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Missing Authentication for Critical Functio... |
| CVE-2026-81440 | HIGH | 7.3 | — | Sep 17, 2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerability... |
| CVE-2026-92903 | HIGH | 8.2 | — | Sep 17, 2026 | Improper input validation in Snowflake CLI versions prior to 3.27.0 allowed unsanitized user-controlled values to be int... |
| CVE-2026-81474 | HIGH | 7.8 | — | Sep 17, 2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Heap-based Buffer Overflow vulnerability. A... |
| CVE-2026-66269 | HIGH | 7.3 | — | Sep 17, 2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Externally-Controlled Input to Selec... |
| CVE-2026-78428 | HIGH | 8 | — | Sep 17, 2026 | For users authenticated through SAML or OpenID Connect (OIDC), this vulnerability can result in one user receiving anoth... |
| CVE-2026-78425 | HIGH | 7.6 | — | Sep 17, 2026 | Authorised users of outside applications behind the same corporate identity provider (IdP), for example, a wiki, a ticke... |
| CVE-2026-50610 | HIGH | 7.4 | — | Sep 17, 2026 | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense d... |
| CVE-2026-50609 | HIGH | 7.4 | — | Sep 17, 2026 | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. ... |
| CVE-2026-86320 | HIGH | 7.8 | — | Sep 17, 2026 | A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. ... |
| CVE-2026-50605 | HIGH | 7.4 | — | Sep 17, 2026 | A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. Insu... |
| CVE-2026-87963 | HIGH | 8.6 | 0.3% | Sep 17, 2026 | The Yo WordPress plugin from 1.1 through 1.3.1 does not sanitize or parameterize the username request parameter before u... |
| CVE-2026-86801 | HIGH | 8.8 | — | Sep 17, 2026 | The To Do List Member WordPress plugin from 1.4 through 1.6 ships a file upload endpoint that does not load WordPress an... |
| CVE-2026-91014 | HIGH | 7.1 | — | Sep 17, 2026 | The Realtyna Organic IDX plugin + WPL Real Estate WordPress plugin before 5.4.2 does not sanitise and escape some of its... |
| CVE-2026-88904 | HIGH | 8.8 | — | Sep 17, 2026 | The PuppyFW WordPress plugin through 0.4.4 does not have proper authorisation on one of its REST routes, which tests the... |
| CVE-2026-88792 | HIGH | 8.8 | — | Sep 17, 2026 | The Dictionary WordPress plugin through 1.0 does not have authorisation, sanitisation or escaping in place when adding o... |
| CVE-2026-87786 | HIGH | 8.8 | — | Sep 17, 2026 | The Dewa Kirim WordPress plugin through 1.0.0 does not escape delivery coordinates submitted at checkout before outputt... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now