2026 CVE Vulnerabilities
64,824 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-17495 | MEDIUM | 5.9 | 0.4% | Sep 15, 2026 | moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. In versions 2.29.2 thro... |
| CVE-2026-16593 | MEDIUM | 6.8 | 0.2% | Sep 15, 2026 | The WP Directory Kit WordPress plugin through 1.5.7 does not sanitize and escape some widget settings before using them ... |
| CVE-2026-15758 | MEDIUM | 5.3 | 0.3% | Sep 15, 2026 | The 3D FlipBook – PDF Embedder, PDF Flipbook Viewer, Flipbook Image Gallery plugin for WordPress is vulnerable to Sensit... |
| CVE-2026-90881 | MEDIUM | 5.3 | 0.4% | Sep 15, 2026 | A weakness has been identified in D-Link DIR-882 up to 20260814. Impacted is the function main of the file /HNAP1/dllog.... |
| CVE-2026-90878 | MEDIUM | 4.3 | 0.3% | Sep 15, 2026 | A vulnerability was determined in vllm-project vLLM up to 0.27.1. This affects an unknown part of the file /v1/chat/comp... |
| CVE-2026-90857 | MEDIUM | 6.3 | 0.2% | Sep 15, 2026 | A vulnerability was detected in SourceCodester College Notes Gallery Management System 1.0. Affected is an unknown funct... |
| CVE-2026-88261 | MEDIUM | 5.1 | 0.2% | Sep 15, 2026 | Improper input validation vulnerability in bizwell xClick allows Stored XSS. This issue affects xClick: R2, R3, and R3.... |
| CVE-2026-91774 | MEDIUM | 4.3 | 0.2% | Sep 15, 2026 | Yao through v1.0.0-rc22 authenticates but fails to authorize the GET /user/teams/:id endpoint, allowing any logged-in us... |
| CVE-2026-91773 | MEDIUM | 4.3 | 0.2% | Sep 15, 2026 | Soft Serve versions 0.7.1 through 0.11.6 fail to scope Git LFS lock queries by repository, allowing authenticated users ... |
| CVE-2026-91772 | MEDIUM | 6.1 | 0.2% | Sep 15, 2026 | Halo through 2.26.1 contains an open redirect vulnerability in the anonymous thumbnail endpoint that fails to validate t... |
| CVE-2026-91770 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | IceHRM before 36.0.0 fails to validate employee ownership on seven REST sub-resource endpoints, allowing authenticated e... |
| CVE-2026-90851 | MEDIUM | 6.3 | 0.2% | Sep 15, 2026 | A flaw has been found in PHPGurukul Hostel Management System 3.0. This affects an unknown part of the file /admin/includ... |
| CVE-2026-90848 | MEDIUM | 4.3 | 0.3% | Sep 15, 2026 | A weakness has been identified in Governikus AusweisApp up to 2.5.4. Affected is an unknown function of the component St... |
| CVE-2026-91750 | MEDIUM | 6.5 | 0.3% | Sep 15, 2026 | WeKnora before 0.7.0 fails to re-validate HTTP redirect targets in the POST /api/v1/knowledge-bases/:id/knowledge/url en... |
| CVE-2026-85657 | MEDIUM | 5.4 | 0.1% | Sep 15, 2026 | The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vu... |
| CVE-2026-85575 | MEDIUM | 6.4 | 0.2% | Sep 15, 2026 | The ShopEngine Elementor WooCommerce Builder Addon – All in One WooCommerce Solution with eCommerce Templates & Woo Widg... |
| CVE-2026-91201 | MEDIUM | 5.4 | 0.1% | Sep 14, 2026 | DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint ... |
| CVE-2026-91199 | MEDIUM | 5 | 0.2% | Sep 14, 2026 | Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetch... |
| CVE-2026-91198 | MEDIUM | 5.3 | 0.2% | Sep 14, 2026 | GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by una... |
| CVE-2026-91197 | MEDIUM | 6.5 | 0.5% | Sep 14, 2026 | Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFa... |
| CVE-2026-90831 | MEDIUM | 5.3 | 0.2% | Sep 14, 2026 | A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the fi... |
| CVE-2026-90830 | MEDIUM | 5.3 | 0.2% | Sep 14, 2026 | A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of t... |
| CVE-2026-90829 | MEDIUM | 5.3 | 0.2% | Sep 14, 2026 | A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the f... |
| CVE-2026-81900 | MEDIUM | 6.1 | 0.3% | Sep 14, 2026 | Concrete CMS before 9.5.3 applied only trim() to the YouTube block's stored width and height values and printed them int... |
| CVE-2026-18116 | MEDIUM | 6.1 | 0.3% | Sep 14, 2026 | Concrete CMS 8.3.0 to 9.5.2 stored calendar event names without sanitization and rendered them without HTML escaping in ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now