2026 CVE Vulnerabilities
65,279 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-102261 | MEDIUM | 5.4 | — | Sep 29, 2026 | A flaw has been found in owen2345 Camaleon CMS up to 2.9.2. Impacted is the function crop of the file app/controllers/ca... |
| CVE-2026-97029 | MEDIUM | 5.7 | — | Sep 29, 2026 | Flatpak's process ID namespace separation does not prevent a sandboxed app's kill(0, signal) or killpg(0, signal) calls ... |
| CVE-2026-97024 | HIGH | 7.1 | — | Sep 29, 2026 | A path traversal vulnerability in Flatpak's handling of the files/etc directory during app deployment allows a malicious... |
| CVE-2026-102422 | HIGH | 8.1 | — | Sep 29, 2026 | shell-quote's `quote()` function emits a `{ comment }` token as `#` followed by its text, which comments out the rest of... |
| CVE-2026-102414 | LOW | 3.7 | — | Sep 29, 2026 | pbkdf2 through 3.1.6 re-hashes passwords longer than the digest's block size on every iteration in its JavaScript fallba... |
| CVE-2026-102249 | HIGH | 7.3 | — | Sep 29, 2026 | A security flaw has been discovered in REBUILD up to 4.4.11. This vulnerability affects unknown code of the file /common... |
| CVE-2026-102248 | HIGH | 7.3 | — | Sep 29, 2026 | A vulnerability was identified in Rebuild up to 4.4.7/4.5.0-beta5. This affects an unknown part of the file /user/login ... |
| CVE-2026-102247 | MEDIUM | 6.8 | — | Sep 29, 2026 | A vulnerability was detected in FastAdmin 1.6.1.20250430/1.6.5.20260602. This affects an unknown function of the file ap... |
| CVE-2026-102245 | HIGH | 7.3 | — | Sep 29, 2026 | A weakness has been identified in MODSetter SurfSense up to 2.0.3. The affected element is an unknown function of the fi... |
| CVE-2026-97685 | HIGH | 7.1 | — | Sep 29, 2026 | An authenticated LimeSurvey Community Edition 7.3.0 user allowed to create surveys can use their own survey as an author... |
| CVE-2026-102244 | MEDIUM | 4.3 | — | Sep 29, 2026 | A security flaw has been discovered in MODSetter SurfSense up to 0.0.36. Impacted is an unknown function of the file sur... |
| CVE-2026-102243 | HIGH | 7.4 | — | Sep 29, 2026 | A vulnerability was identified in MODSetter SurfSense up to 2.0.3. This issue affects some unknown processing of the fil... |
| CVE-2026-102241 | LOW | 2.7 | — | Sep 29, 2026 | A vulnerability was determined in Netcore NAP930 0.1.241010.141410. This vulnerability affects unknown code of the file ... |
| CVE-2026-96326 | HIGH | 7.2 | — | Sep 29, 2026 | The HT Contact Form – Drag & Drop Form Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scr... |
| CVE-2026-102240 | CRITICAL | 10 | — | Sep 29, 2026 | A vulnerability was found in Netcore NAP930 0.1.241010.141410. This affects the function eval of the file /www/cgi-bin/n... |
| CVE-2026-101878 | HIGH | 7.5 | — | Sep 29, 2026 | Bitwarden Server 2025.6.0 before 2026.5.0 declares the @ExternalId parameter of the User_ReadBySsoUserOrganizationIdExte... |
| CVE-2026-101860 | HIGH | 8.8 | — | Sep 29, 2026 | A vulnerability was found in RaspAP raspap-webgui up to 3.5.5. Affected by this issue is the function PluginInstaller::a... |
| CVE-2026-101859 | MEDIUM | 5.4 | — | Sep 29, 2026 | A vulnerability has been found in RaspAP raspap-webgui up to 3.5.5. Affected by this vulnerability is the function escap... |
| CVE-2026-101858 | MEDIUM | 4.7 | — | Sep 29, 2026 | A flaw has been found in RaspAP raspap-webgui up to 3.5.5. Affected is the function WiFiManager::writeWpaSupplicant of t... |
| CVE-2026-101354 | CRITICAL | 9.6 | — | Sep 29, 2026 | A security flaw has been discovered in FAST FAC1203R 20200116_2.0.4. The affected element is the function _tWlanTask of ... |
| CVE-2026-102374 | MEDIUM | 6.1 | — | Sep 29, 2026 | GestSup versions before 3.2.62 contain a stored cross-site scripting vulnerability in the IMAP OAuth connector that doub... |
| CVE-2026-102373 | MEDIUM | 6.5 | — | Sep 29, 2026 | GestSup versions before 3.2.62 fail to validate ticket ownership when loading comments via the threadedit parameter in t... |
| CVE-2026-102372 | MEDIUM | 6.1 | — | Sep 29, 2026 | GestSup versions before 3.2.62 fail to properly sanitize HTML email bodies in the IMAP LOGIN connector, allowing unauthe... |
| CVE-2026-101281 | HIGH | 7.3 | — | Sep 29, 2026 | A flaw has been found in Trusted Domain Project OpenDMARC up to 1.4.2. Affected by this vulnerability is the function op... |
| CVE-2026-101280 | HIGH | 7.3 | — | Sep 29, 2026 | A vulnerability was detected in Trusted Domain Project OpenDMARC up to 1.4.2. Affected is the function opendmarc_policy_... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now