2026 CVE Vulnerabilities
64,824 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-92077 | MEDIUM | 6.5 | 0.2% | Sep 15, 2026 | Denial-of-service in the SVG component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunderbird 156,... |
| CVE-2026-92070 | MEDIUM | 4.3 | 0.1% | Sep 15, 2026 | Information disclosure in the Networking component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thun... |
| CVE-2026-92069 | MEDIUM | 5.4 | 0.1% | Sep 15, 2026 | Spoofing issue in the DOM: Navigation component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thunder... |
| CVE-2026-92068 | MEDIUM | 5.4 | 0.1% | Sep 15, 2026 | Site isolation issue in the Reader Mode component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, Thund... |
| CVE-2026-92063 | MEDIUM | 6.5 | 0.1% | Sep 15, 2026 | Denial-of-service in the Audio/Video component. This vulnerability was fixed in Firefox 156 and Thunderbird 156. |
| CVE-2026-92039 | MEDIUM | 6.3 | 0.2% | Sep 15, 2026 | Mitigation bypass in the DOM: Notifications component. This vulnerability was fixed in Firefox 156, Firefox ESR 153.3, T... |
| CVE-2026-92031 | MEDIUM | 6.5 | 0.2% | Sep 15, 2026 | Information disclosure in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 156, Firefox ESR 140... |
| CVE-2026-92030 | MEDIUM | 5.4 | 0.2% | Sep 15, 2026 | Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 156, Firef... |
| CVE-2026-92005 | MEDIUM | 5.3 | 0.2% | Sep 15, 2026 | Use-after-free in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 156, Firefox ESR 140.16... |
| CVE-2026-15609 | MEDIUM | 6.4 | 0.2% | Sep 15, 2026 | The Bridge - Creative Multipurpose WordPress Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via ... |
| CVE-2026-92003 | MEDIUM | 6.9 | — | Sep 15, 2026 | Affected versions of MISP do not consistently apply the existing authentication-failure logging throttle. Two API auth... |
| CVE-2026-92002 | MEDIUM | 5.1 | — | Sep 15, 2026 | Affected versions of MISP use Redis to throttle repeated authentication-failure log entries. The intent is to avoid exce... |
| CVE-2026-91997 | MEDIUM | 5.3 | 0.4% | Sep 15, 2026 | evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always eval... |
| CVE-2026-91994 | MEDIUM | 6.5 | 0.4% | Sep 15, 2026 | Semaphore UI through 2.19.12 exempts GET and HEAD requests from project resource permission checks in GetMustCanMiddlewa... |
| CVE-2026-91993 | MEDIUM | 4.3 | 0.3% | Sep 15, 2026 | Jpom through 2.11.12 fails to validate workspace ownership when resolving repositoryId on the /build/branch-list endpoin... |
| CVE-2026-91922 | MEDIUM | 6.1 | 0.3% | Sep 15, 2026 | Steedos Platform through 3.0.15-beta.47 contains a reflected cross-site scripting vulnerability in the anonymous /api/pa... |
| CVE-2026-91786 | MEDIUM | 6.1 | 0.1% | Sep 15, 2026 | A flaw was found in GNOME Shell. When processing icons from a remote search provider via D-Bus, the system fails to vali... |
| CVE-2026-86818 | MEDIUM | 4.8 | 0.2% | Sep 15, 2026 | fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv, that added a mailto scheme parse... |
| CVE-2026-86472 | MEDIUM | 4.8 | 0.2% | Sep 15, 2026 | fast-uri is a dependency-free RFC 3986 URI parser for Node.js, used by Fastify and ajv. In versions before 2.4.7, from 3... |
| CVE-2026-80489 | MEDIUM | 5.9 | 0.4% | Sep 15, 2026 | Converting crafted EUC_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the G... |
| CVE-2026-77117 | MEDIUM | 5.9 | 0.4% | Sep 15, 2026 | Converting crafted SHIFT_JISX0213 input to UCS-4 or the internal wide character encoding, for example with iconv, in the... |
| CVE-2026-52828 | MEDIUM | 5.3 | 0.4% | Sep 15, 2026 | Kimai is an open-source time tracking application. Prior to 2.58.0, ExportController::createExportTemplate() and ExportC... |
| CVE-2026-52826 | MEDIUM | 5.3 | 0.3% | Sep 15, 2026 | Kimai is an open-source time tracking application. Prior to 2.57.0, GET or POST requests to /en/admin/project/{id}/rate/... |
| CVE-2026-52825 | MEDIUM | 5.3 | 0.3% | Sep 15, 2026 | Kimai is an open-source time tracking application. Prior to 2.58.0, POST /api/teams/{id}/members/{userId} and POST /api/... |
| CVE-2026-52823 | MEDIUM | 5.3 | 0.2% | Sep 15, 2026 | Kimai is an open-source time tracking application. Prior to 2.58.0, TimesheetController exposes GET /api/timesheets/{id}... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now