2026 CVE Vulnerabilities
65,279 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-4523 | LOW | 3.7 | — | Sep 29, 2026 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 19.2.7, 19.3 before 19.3.3, and ... |
| CVE-2026-19547 | HIGH | 7 | — | Sep 29, 2026 | Ghostscript for Windows is vulnerable to local privilege escalation through PostScript resource file hijacking. Due to t... |
| CVE-2026-15390 | CRITICAL | 9 | — | Sep 29, 2026 | Das U-Boot with CONFIG_IP_DEFRAG=y parameter fails to clear IP reassembly state after delivering a complete datagram. An... |
| CVE-2026-11796 | MEDIUM | 5.1 | — | Sep 29, 2026 | Asset Suite allows unauthenticated users to access PropertiesReloadServlet, CacheFlushServlet, MetadataCacheFlushServlet... |
| CVE-2026-10518 | MEDIUM | 4.3 | — | Sep 29, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 19.2.7, 19.3 before 19.3.3, and 19.4... |
| CVE-2026-102474 | MEDIUM | 4 | — | Sep 29, 2026 | A flaw was found in dash. The printf builtin reserves four bytes before converting a Unicode \u or \U escape, but the mu... |
| CVE-2026-102473 | MEDIUM | 5.5 | — | Sep 29, 2026 | A flaw was found in dash. When built without libc fnmatch, the internal pmatch() matcher implements * by unbounded recur... |
| CVE-2026-96440 | HIGH | 7.1 | — | Sep 29, 2026 | Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp AP... |
| CVE-2026-96431 | CRITICAL | 9.3 | — | Sep 29, 2026 | Unrestricted Upload of File with Dangerous Type in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agent... |
| CVE-2026-96430 | HIGH | 8.7 | — | Sep 29, 2026 | Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2... |
| CVE-2026-96429 | CRITICAL | 9.3 | — | Sep 29, 2026 | SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08... |
| CVE-2026-96428 | CRITICAL | 9.3 | — | Sep 29, 2026 | SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 ... |
| CVE-2026-92142 | — | — | — | Sep 29, 2026 | Apache Karaf exposes a JMX MBeanServer guarded by KarafMBeanServerGuard, which enforces role-based access control (RBAC)... |
| CVE-2026-91085 | — | — | — | Sep 29, 2026 | Apache Karaf's shell/SSH command security is enforced by per-scope ACL configuration files (etc/org.apache.karaf.command... |
| CVE-2026-91048 | — | — | — | Sep 29, 2026 | The jdbc shell command scope shipped no org.apache.karaf.command.acl.jdbc.cfg. Karaf's command guard (SecuredSessionFact... |
| CVE-2026-91012 | — | — | — | Sep 29, 2026 | org.apache.karaf.config.core.impl.ConfigRepositoryImpl#update(pid, properties), which backs the "config" MBean and the c... |
| CVE-2026-84154 | CRITICAL | 9.9 | — | Sep 29, 2026 | A Code Injection vulnerability affecting GEOVIA Geospatial Data Manager from Release 3DEXPERIENCE R2024x through Release... |
| CVE-2026-101169 | HIGH | 8.7 | — | Sep 29, 2026 | In affected versions of Octopus Server, an authenticated user with permissions to edit an Environment or Project can set... |
| CVE-2026-86158 | HIGH | 7.7 | — | Sep 29, 2026 | Missing authentication in the local .NET backend (Fiddler.WebUi) of Progress Software Fiddler Everywhere 8.0.2 allows a ... |
| CVE-2026-86157 | MEDIUM | 5.6 | — | Sep 29, 2026 | Exposure of privileged IPC functionality in Progress Telerik Fiddler Everywhere before version 8.2.0 allows a local, low... |
| CVE-2026-102293 | HIGH | 7.3 | — | Sep 29, 2026 | A vulnerability was identified in realjerrytang tacomall 1.0.0. Impacted is the function OrgStaffServiceImpl.add of the ... |
| CVE-2026-102292 | MEDIUM | 4.3 | — | Sep 29, 2026 | A flaw has been found in coolbeans1212 MateisHomePage-Website up to ea2a4226deeca27ab1fb9df0552ec76444547811. Affected b... |
| CVE-2026-102290 | LOW | 3.5 | — | Sep 29, 2026 | A vulnerability was determined in CodeCanyon Rocket LMS up to 2.2. This affects an unknown function of the component Stu... |
| CVE-2026-102264 | LOW | 3.5 | — | Sep 29, 2026 | A vulnerability was found in mwasikz robo-cafe-rms up to 228c44a02823f04e85db32b7137809a2856148fc. The impacted element ... |
| CVE-2026-102263 | MEDIUM | 4.7 | — | Sep 29, 2026 | A vulnerability has been found in mwasikz robo-cafe-rms up to 228c44a02823f04e85db32b7137809a2856148fc. The affected ele... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now