2026 CVE Vulnerabilities
64,729 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-92842 | MEDIUM | 5.9 | — | Sep 25, 2026 | The convert.base64-encode, convert.quoted-printable-encode and convert.quoted-printable-decode stream filters accept a l... |
| CVE-2026-91768 | MEDIUM | 6.5 | — | Sep 25, 2026 | The IPv6 branch of the FastCGI client access check compares only the first 12 bytes of a 16-byte IPv6 address, so listen... |
| CVE-2026-63432 | MEDIUM | 6.5 | — | Sep 25, 2026 | Horilla is an HR and CRM software. From 1.0.0 until 1.6.0 and 2.0.0, the get_mail_preview handlers in recruitment/views/... |
| CVE-2026-63431 | MEDIUM | 6.5 | — | Sep 25, 2026 | Horilla is an HR and CRM software. In 1.5.0-85 and earlier, payroll/views/component_views.py does not consistently autho... |
| CVE-2026-100502 | MEDIUM | 5 | — | Sep 25, 2026 | Flame through 2.4.0 contains an insufficient session expiration vulnerability in the login endpoint that allows attacker... |
| CVE-2026-100501 | MEDIUM | 6.5 | — | Sep 25, 2026 | Flame through 2.4.0 contains an improper restriction of excessive authentication attempts vulnerability in the POST /api... |
| CVE-2026-100418 | MEDIUM | 5.3 | — | Sep 25, 2026 | Flame through 2.4.0 contains an information exposure vulnerability in the unauthenticated GET /api/config endpoint that ... |
| CVE-2026-100383 | MEDIUM | 4.8 | 0.3% | Sep 25, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2026-100381 | MEDIUM | 5.3 | 0.3% | Sep 25, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2026-96879 | MEDIUM | 6.9 | — | Sep 25, 2026 | Improper removal of sensitive information before storage or transfer vulnerability in Wikimedia Foundation's Mediawiki -... |
| CVE-2026-91769 | MEDIUM | 4.3 | — | Sep 25, 2026 | PHP's OpenSSL stream peer verification checks the certificate's subjectAltName entries first and, whenever no entry matc... |
| CVE-2026-91767 | MEDIUM | 6.5 | — | Sep 25, 2026 | php_openssl_matches_wildcard_name() in ext/openssl/xp_ssl.c underflows the length argument passed to memchr() when a TLS... |
| CVE-2026-91766 | MEDIUM | 5.9 | — | Sep 25, 2026 | When the http:// stream wrapper follows a redirect it forwards the user-supplied Authorization, Cookie and Proxy-Authori... |
| CVE-2026-6103 | MEDIUM | 4.3 | — | Sep 25, 2026 | phar_tar_number() parses the octal size field of a TAR header into a uint32_t with no overflow check. The field is 11 oc... |
| CVE-2026-17545 | MEDIUM | 6.9 | — | Sep 25, 2026 | On Windows, PHP's filesystem and stream APIs do not reject reserved device names such as CON, PRN, AUX, NUL, COM1 to COM... |
| CVE-2026-100388 | MEDIUM | 5.4 | — | Sep 25, 2026 | RustDesk versions before 1.5.0 fail to properly validate file transfer permissions on incoming file clipboard messages i... |
| CVE-2026-100380 | MEDIUM | 5.3 | 0.3% | Sep 25, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2026-100379 | MEDIUM | 5.3 | 0.3% | Sep 25, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Wikipedia Android App a... |
| CVE-2026-100378 | MEDIUM | 5.3 | 0.3% | Sep 25, 2026 | Missing Authorization vulnerability in Wikimedia Foundation Mediawiki - Translate Extension allows Accessing Functionali... |
| CVE-2026-100377 | MEDIUM | 6.9 | 0.3% | Sep 25, 2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - WikiLambda ... |
| CVE-2026-100376 | MEDIUM | 4.8 | 0.3% | Sep 25, 2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia F... |
| CVE-2026-96878 | MEDIUM | 6.9 | — | Sep 25, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo ... |
| CVE-2026-96877 | MEDIUM | 6.9 | — | Sep 25, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo ... |
| CVE-2026-96876 | MEDIUM | 6.9 | — | Sep 25, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo ... |
| CVE-2026-96875 | MEDIUM | 6.9 | — | Sep 25, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now