2026 CVE Vulnerabilities
64,824 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-89063 | HIGH | 7.5 | 0.4% | Sep 16, 2026 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Insecure Direct Obje... |
| CVE-2026-78088 | HIGH | 8.8 | 0.6% | Sep 16, 2026 | The Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe plugin for WordPress is vulnerable to Unaut... |
| CVE-2026-18595 | HIGH | 7.2 | 0.3% | Sep 16, 2026 | The WP-Lister Lite for eBay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via AJAX Cron Handler Requ... |
| CVE-2026-86108 | HIGH | 8 | 0.8% | Sep 16, 2026 | Insufficient validation of inputs supplied through affected VeloCloud Edge management and configuration workflows may al... |
| CVE-2026-92299 | HIGH | 7.4 | 0.3% | Sep 16, 2026 | @jitsi/electron-sdk before 10.0.5 exposes getDesktopSources() via contextBridge without requiring an active getDisplayMe... |
| CVE-2026-92215 | HIGH | 7.3 | 0.4% | Sep 16, 2026 | A vulnerability has been found in a2ui-project a2ui up to 0.10.7. Affected by this vulnerability is the function httpx.g... |
| CVE-2026-73459 | HIGH | 7.4 | 0.2% | Sep 16, 2026 | On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially c... |
| CVE-2026-73446 | HIGH | 7.4 | 0.2% | Sep 16, 2026 | On affected platforms running Arista EOS with IS-IS configured on a broadcast interface, an unauthenticated attacker can... |
| CVE-2026-85893 | HIGH | 8.8 | 0.8% | Sep 15, 2026 | Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges over a network. |
| CVE-2026-69486 | HIGH | 8.8 | 0.8% | Sep 15, 2026 | Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a net... |
| CVE-2026-92248 | HIGH | 7.8 | 0.2% | Sep 15, 2026 | A flaw was found in the file-psd plugin in GIMP. When generating a thumbnail preview for a specially crafted PSD (Photos... |
| CVE-2026-83408 | HIGH | 8.1 | 0.3% | Sep 15, 2026 | Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The suppo... |
| CVE-2026-83368 | HIGH | 7 | 0.2% | Sep 15, 2026 | Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVM product of Oracle Java SE... |
| CVE-2026-83357 | HIGH | 8.1 | 0.4% | Sep 15, 2026 | Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The suppo... |
| CVE-2026-76870 | HIGH | 7.1 | 0.3% | Sep 15, 2026 | Netcore NR255-V version 1.5.130703 contains an out-of-bounds read vulnerability in the mtd_write pre-flash validation ro... |
| CVE-2026-76869 | HIGH | 7.2 | 0.4% | Sep 15, 2026 | Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in reboot_timer_set.cgi caused by improper ssc... |
| CVE-2026-76866 | HIGH | 7.2 | 0.4% | Sep 15, 2026 | Netcore NR255-V firmware version 1.5.130703 builds root-run command lines from unquoted user-supplied DDNS input in DDNS... |
| CVE-2026-76862 | HIGH | 8.8 | 0.4% | Sep 15, 2026 | Netcore NR255-V version 1.5.130703 contains an os command argument injection vulnerability in the Nettools tcpdump launc... |
| CVE-2026-76861 | HIGH | 8.8 | 0.5% | Sep 15, 2026 | Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in ntools_tcpdump_start_set.cgi caused by an u... |
| CVE-2026-76860 | HIGH | 8.8 | 0.4% | Sep 15, 2026 | Netcore NR255-V version 1.5.130703 contains a stack-based buffer overflow in wake_up_set.cgi caused by unbounded tokeniz... |
| CVE-2026-76856 | HIGH | 8.1 | 0.2% | Sep 15, 2026 | Netcore NR255-V firmware version 1.5.130703 contains a cross-site request forgery vulnerability affecting the wan_config... |
| CVE-2026-76853 | HIGH | 8.1 | 0.2% | Sep 15, 2026 | Netcore NR268 firmware version 1.7.121109 contains a security check bypass vulnerability in the parame_put_file.cgi rest... |
| CVE-2026-76852 | HIGH | 8.8 | 0.2% | Sep 15, 2026 | Netcore NR268 firmware version 1.7.121109 has an improper integrity verification flaw in mtd_write allowing forged firmw... |
| CVE-2026-10144 | HIGH | 7.8 | 1.6% | Sep 15, 2026 | Rsbuild before 2.0.9 contains a command injection vulnerability that allows attackers to execute arbitrary OS commands b... |
| CVE-2026-92000 | HIGH | 7.5 | 0.7% | Sep 15, 2026 | adm-zip versions 0.5.14 through 0.6.0 fail to apply zlib decompression output limits when ZIP entries declare zero uncom... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now