2026 CVE Vulnerabilities
64,785 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-92132 | MEDIUM | 5.4 | — | Sep 16, 2026 | Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected i... |
| CVE-2026-92131 | MEDIUM | 4.2 | — | Sep 16, 2026 | Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does not restrict the library path provided to ... |
| CVE-2026-89030 | MEDIUM | 4.3 | 0.3% | Sep 16, 2026 | Adenion Blog2Social plugin for WordPress before 9.1.0 exposes the email addresses of all registered WordPress users to l... |
| CVE-2026-89029 | MEDIUM | 4.3 | 0.3% | Sep 16, 2026 | Adenion Blog2Social plugin for WordPress before 9.1.0 allows low-privileged users to enumerate WordPress user accounts. ... |
| CVE-2026-85104 | MEDIUM | 5.3 | — | Sep 16, 2026 | In Sooma 2GEN brain stimulator, an attacker within Bluetooth range can make unauthenticated changes to brain stimulation... |
| CVE-2026-78301 | MEDIUM | 5.8 | — | Sep 16, 2026 | A malformed zone may contain an NS or DNAME node above its origin, which `named` treats as a zone cut. If an attacker in... |
| CVE-2026-56719 | MEDIUM | 6.5 | 0.4% | Sep 16, 2026 | MikroTik RouterOS before 7.24 contains an out-of-bounds read vulnerability in the userspace SMB daemon that allows unaut... |
| CVE-2026-19941 | MEDIUM | 5.9 | — | Sep 16, 2026 | An inapplicable NSEC record may be accepted by a `named` resolver as proof that no wildcard exists, which could allow an... |
| CVE-2026-19662 | MEDIUM | 5.9 | — | Sep 16, 2026 | An attacker may be able to cause a `named` resolver to abort. The attack requires inducing the victim resolver to send m... |
| CVE-2026-92361 | MEDIUM | 4.3 | 0.5% | Sep 16, 2026 | A security vulnerability has been detected in ag-ui-protocol ag-ui 1.0. This affects an unknown function of the file sdk... |
| CVE-2026-92360 | MEDIUM | 6.3 | 0.2% | Sep 16, 2026 | A weakness has been identified in ag-ui-protocol ag-ui 1.0. The impacted element is the function prepareRunAgentInput of... |
| CVE-2026-73169 | MEDIUM | 6.3 | 0.5% | Sep 16, 2026 | Nozomi Networks Labs identified a CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scrip... |
| CVE-2026-92463 | MEDIUM | 6.5 | 0.5% | Sep 16, 2026 | yshop-crm through 2.1.3 contains an authorization failure in the GET /admin-api/system/user/page endpoint where the @Pre... |
| CVE-2026-92462 | MEDIUM | 6.5 | 0.4% | Sep 16, 2026 | yshop-crm through 2.1.3 fails to enforce authorization checks on the CrmFlowController deleteFlowStep endpoint, allowing... |
| CVE-2026-92461 | MEDIUM | 4.3 | 0.3% | Sep 16, 2026 | yshop-crm through 2.1.3 contains a missing authorization vulnerability in the GET /admin-api/crm/flow/flow-users endpoin... |
| CVE-2026-92460 | MEDIUM | 6.5 | 0.3% | Sep 16, 2026 | yshop-crm through 2.1.3 fails to enforce authorization on the GET /admin-api/crm/operatelog/page endpoint, allowing any ... |
| CVE-2026-92459 | MEDIUM | 6.5 | 0.4% | Sep 16, 2026 | yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmCluesController receiveCustomer endpoin... |
| CVE-2026-92458 | MEDIUM | 4.3 | 0.3% | Sep 16, 2026 | yshop-crm through 2.1.3 contains a missing authorization vulnerability in the StoreProductController onSale handler that... |
| CVE-2026-92457 | MEDIUM | 6.5 | 0.3% | Sep 16, 2026 | yshop-crm through 2.1.3 contains a missing authorization vulnerability in the CrmInvoiceController issueInvoice endpoint... |
| CVE-2026-92455 | MEDIUM | 4.3 | 0.3% | Sep 16, 2026 | yshop-crm through 2.1.3 fails to enforce authorization on the sendSms and sendMail endpoints in CrmCustomerController, a... |
| CVE-2026-92357 | MEDIUM | 4.3 | — | Sep 16, 2026 | A vulnerability was identified in a2ui-project a2ui 0.8/0.9/1.0. Impacted is an unknown function of the file model-proce... |
| CVE-2026-92356 | MEDIUM | 4.3 | — | Sep 16, 2026 | A vulnerability was determined in a2ui-project a2ui 0.9/0.9.1. This issue affects the function updateComponents of the f... |
| CVE-2026-86107 | MEDIUM | 5.9 | — | Sep 16, 2026 | The VeloCloud Edge and Gateway exhibit an out-of-bounds write vulnerability when processing tunneled IP fragments betwee... |
| CVE-2026-86443 | MEDIUM | 6.9 | 0.1% | Sep 16, 2026 | Cleartext storage of sensitive information in the DuoxMe application for Android, in versions prior to 4.3.4, allows an ... |
| CVE-2026-84501 | MEDIUM | 5.3 | 0.2% | Sep 16, 2026 | An unauthenticated attacker can inject arbitrary fake log lines into Apache ZooKeeper's operational log by sending a cra... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now