2026 CVE Vulnerabilities
64,729 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84903 | LOW | 2.7 | — | Sep 18, 2026 | The King Addons for Elementor WordPress plugin before 51.1.81 does not perform any capability, post-status, or password... |
| CVE-2026-81340 | LOW | 3.8 | — | Sep 18, 2026 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 does not perform per-object ownership or capability... |
| CVE-2026-68493 | LOW | 3.1 | — | Sep 18, 2026 | After guessing a 62^15 complex unique identifier, a malicious logged in user was able to retrieve a list of memberships ... |
| CVE-2026-93394 | LOW | 3.7 | 0.3% | Sep 17, 2026 | A flaw in libmongoc's SCRAM authentication implementation caused the client to continue the authentication handshake and... |
| CVE-2026-93384 | LOW | 3.7 | — | Sep 17, 2026 | Server-side request forgery in Omnibox in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker l... |
| CVE-2026-93380 | LOW | 3.1 | 0.2% | Sep 17, 2026 | Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised the r... |
| CVE-2026-93378 | LOW | 3.1 | 0.2% | Sep 17, 2026 | Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allowed a remote attacker who had compromised t... |
| CVE-2026-45723 | LOW | 2.7 | 0.4% | Sep 17, 2026 | Omni manages Kubernetes on bare metal, virtual machines, or in a cloud. Prior to 1.6.6 and 1.7.3, managementServer.Creat... |
| CVE-2026-55061 | LOW | 1 | 0.2% | Sep 17, 2026 | uniget is a universal installer and updater for (container) tools. Prior to 0.27.6, the hooks edit command in cmd/uniget... |
| CVE-2026-54649 | LOW | 2.1 | 0.8% | Sep 17, 2026 | punchin-email is a Cloudflare Email Worker that provides two-way role aliases while relaying mail to a private inbox. Pr... |
| CVE-2026-85716 | LOW | 3.7 | 0.4% | Sep 17, 2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HT... |
| CVE-2026-54579 | LOW | 2.3 | 0.2% | Sep 17, 2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, ping() in libmport/ping.c accepted ICMP replies without valida... |
| CVE-2026-54578 | LOW | 2 | — | Sep 17, 2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, mport_verify_package() in libmport/verify.c could continue aft... |
| CVE-2026-54577 | LOW | 2 | 0.2% | Sep 17, 2026 | mport is the MidnightBSD Package Manager. Prior to 2.7.8, the audit command in mport/mport.c computed option-adjusted lo... |
| CVE-2026-75588 | LOW | 2.6 | — | Sep 17, 2026 | Mattermost Desktop App versions <=6.2 6.2.2.0 fail to validate the URL scheme when checking whether a target URL is inte... |
| CVE-2026-61700 | LOW | 3.7 | 0.2% | Sep 17, 2026 | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3... |
| CVE-2026-12284 | LOW | 3.7 | — | Sep 17, 2026 | Mattermost Desktop App versions <=6.2 6.2.2.0 fails to validate the IPC sender in the leaveCall handler which allows a m... |
| CVE-2026-54471 | LOW | 3.5 | — | Sep 17, 2026 | Dell SmartFabric Manager, versions prior to 2.2.1, contains an Improper Handling of Insufficient Permissions or Privileg... |
| CVE-2026-92962 | LOW | 2.1 | — | Sep 17, 2026 | vm2 is a sandbox for running untrusted JavaScript. In vm2 versions up to and including 3.11.3, the defaultSandboxPrepare... |
| CVE-2026-82759 | LOW | 1.8 | — | Sep 17, 2026 | Use of a One-Way Hash with a Predictable Salt vulnerability in team-alembic AshAuthentication allows readers of the audi... |
| CVE-2026-82723 | LOW | 1.8 | — | Sep 17, 2026 | Insertion of Sensitive Information into Log File vulnerability in team-alembic AshAuthentication allows disclosure of us... |
| CVE-2026-81637 | LOW | 2.3 | — | Sep 17, 2026 | Insufficient Session Expiration vulnerability in team-alembic AshAuthentication allows an attacker who obtains a victim'... |
| CVE-2026-81439 | LOW | 3.7 | — | Sep 17, 2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains an Incorrect Authorization vulnerability. A l... |
| CVE-2026-81438 | LOW | 3.7 | — | Sep 17, 2026 | Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains Use of a Broken or Risky Cryptographic Algori... |
| CVE-2026-78426 | LOW | 3.7 | — | Sep 17, 2026 | The NeuVector JWT verifier accepts noncanonical Base64URL encodings of the same RSA signature field. An attacker holding... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now