2026 CVE Vulnerabilities
64,732 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-96875 | MEDIUM | 6.9 | — | Sep 25, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo ... |
| CVE-2026-93682 | MEDIUM | 5.8 | — | Sep 25, 2026 | When the HTTP stream wrapper follows a redirect and the response carries a Location header with an empty value, the redi... |
| CVE-2026-100373 | MEDIUM | 4.1 | — | Sep 25, 2026 | OpenMetadata through 2.0.2 contains a server-side request forgery vulnerability in the URLValidator.validateURL function... |
| CVE-2026-97895 | MEDIUM | 6.3 | — | Sep 25, 2026 | A vulnerability was determined in krayin laravel-crm up to 2.2.5. This affects an unknown part of the file packages/Webk... |
| CVE-2026-84463 | MEDIUM | 6.3 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, a user with Knowledge Base editing r... |
| CVE-2026-84461 | MEDIUM | 6.9 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, the two-factor login step let an att... |
| CVE-2026-84460 | MEDIUM | 5.3 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, any authenticated user can call the ... |
| CVE-2026-63216 | MEDIUM | 5.3 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, unsanitized option labels are render... |
| CVE-2026-63208 | MEDIUM | 5.1 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when a Microsoft Graph request fails... |
| CVE-2026-63207 | MEDIUM | 6.9 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, an authenticated administrator c... |
| CVE-2026-63206 | MEDIUM | 5.3 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, zammad's HTML sanitizer, which block... |
| CVE-2026-63205 | MEDIUM | 5.1 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, when creating or updating an email s... |
| CVE-2026-63006 | MEDIUM | 5.3 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. Prior to 7.1.2, attacker-controlled HTML in inbound ... |
| CVE-2026-61855 | MEDIUM | 5.3 | — | Sep 25, 2026 | Zammad is a web based open source helpdesk/customer support system. In 7.0.3 and 7.1.1, under certain conditions, Zammad... |
| CVE-2026-55217 | MEDIUM | 5.3 | — | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 0.85 until 10.0.26 and 11.0.8, a low-privileged authentica... |
| CVE-2026-53628 | MEDIUM | 5.9 | — | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 0.84 until 10.0.26 and 11.0.8, an administrator holding th... |
| CVE-2026-53627 | MEDIUM | 6 | — | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 11.0.0 until 11.0.8, a low-privileged authenticated user c... |
| CVE-2026-49469 | MEDIUM | 4.6 | — | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 0.70 until 10.0.26 and 11.0.8, an authenticated hotliner o... |
| CVE-2026-45801 | MEDIUM | 5.3 | — | Sep 25, 2026 | GLPI is a free asset and IT management software package. From 0.72 until 10.0.26 and 11.0.8, an authenticated user witho... |
| CVE-2026-100306 | MEDIUM | 5.3 | — | Sep 25, 2026 | TDuck survey form through 6.0 fails to validate write passwords on submission endpoints, enforcing the check only on the... |
| CVE-2026-100305 | MEDIUM | 4.3 | — | Sep 25, 2026 | TDuck survey form through 6.0 fails to enforce form fill-in restrictions on the authenticated submission endpoint POST /... |
| CVE-2026-100304 | MEDIUM | 5.3 | — | Sep 25, 2026 | TDuck survey form 6.0 contains an information disclosure vulnerability in FormAuthUtils.hasPermission that fails open wh... |
| CVE-2026-100303 | MEDIUM | 5.4 | — | Sep 25, 2026 | TDuck survey form through 6.0 lacks authorization checks on FormThemeController write endpoints for global form themes a... |
| CVE-2026-100192 | MEDIUM | 6.5 | — | Sep 25, 2026 | X-SpringBoot through 6.0 exposes appKey and appSecret credentials in the GET /application/manager/select endpoint withou... |
| CVE-2026-97886 | MEDIUM | 6.3 | — | Sep 25, 2026 | A vulnerability has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now