2026 CVE Vulnerabilities
64,848 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-90709 | MEDIUM | 4.7 | — | Sep 14, 2026 | A security vulnerability has been detected in Yot CMS up to 3.3.1. Affected by this issue is the function eval of the fi... |
| CVE-2026-79701 | MEDIUM | 6.9 | 0.3% | Sep 14, 2026 | Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass in Module Context in the Contact, Opt-in and Form Bui... |
| CVE-2026-9812 | MEDIUM | 6.5 | 0.2% | Sep 14, 2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate that a pr... |
| CVE-2026-90891 | MEDIUM | 5.5 | 0.1% | Sep 14, 2026 | ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Improper Access Control vulnerability. Authe... |
| CVE-2026-90890 | MEDIUM | 5.5 | 0.1% | Sep 14, 2026 | ASRock Polychrome SYNC/RGB software utility developed by ASRock Inc. has an Untrusted Pointer Dereference vulnerability.... |
| CVE-2026-90706 | MEDIUM | 6.6 | — | Sep 14, 2026 | A vulnerability was identified in D-Link DWR-M921 1.1.52. This impacts the function formWsc of the file /boafrm/formWsc.... |
| CVE-2026-90705 | MEDIUM | 6.6 | 1.5% | Sep 14, 2026 | A vulnerability was determined in D-Link DWR-M921 1.1.52. This affects the function formsysCmd of the file /boafrm/forms... |
| CVE-2026-81566 | MEDIUM | 5.1 | 0.2% | Sep 14, 2026 | Joomla Extension - joomshaper.com - Missing Access Control in Menu Item Creation in SP Page Builder (Free and Pro) 4.0.0... |
| CVE-2026-81565 | MEDIUM | 6.9 | 0.3% | Sep 14, 2026 | Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Upload in SP Page Builder (Free and Pro) 4.0.... |
| CVE-2026-79700 | MEDIUM | 6.9 | 0.3% | Sep 14, 2026 | Joomla Extension - joomshaper.com - Unauthenticated CAPTCHA Bypass via Request-Controlled CAPTCHA Configuration in SP Pa... |
| CVE-2026-5132 | MEDIUM | 6.5 | 0.2% | Sep 14, 2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit size of unpa... |
| CVE-2026-15814 | MEDIUM | 6.5 | 0.2% | Sep 14, 2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to limit the amount o... |
| CVE-2026-14344 | MEDIUM | 4.3 | 0.2% | Sep 14, 2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce the board-... |
| CVE-2026-14259 | MEDIUM | 4.3 | 0.2% | Sep 14, 2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to enforce board crea... |
| CVE-2026-13417 | MEDIUM | 4.3 | 0.2% | Sep 14, 2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate the type ... |
| CVE-2026-12882 | MEDIUM | 4.3 | 0.2% | Sep 14, 2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to parse Markdown aut... |
| CVE-2026-11993 | MEDIUM | 4.3 | 0.2% | Sep 14, 2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly enforce t... |
| CVE-2026-10556 | MEDIUM | 5.3 | 0.2% | Sep 14, 2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate null entr... |
| CVE-2026-10542 | MEDIUM | 5 | 0.1% | Sep 14, 2026 | Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to validate channel a... |
| CVE-2026-90893 | MEDIUM | 5.1 | 0.2% | Sep 14, 2026 | MISP contains a Cross-Site Request Forgery (CSRF) vulnerability in the UserSettingsController. The actions setTheme, set... |
| CVE-2026-90704 | MEDIUM | 6.6 | — | Sep 14, 2026 | A vulnerability was found in D-Link DWR-M921 1.1.52. The impacted element is the function system of the file /boafrm/for... |
| CVE-2026-68570 | MEDIUM | 6.5 | — | Sep 14, 2026 | Incorrect Authorization vulnerability in Apache Doris allows an authenticated user to bypass privilege checks and access... |
| CVE-2026-90700 | MEDIUM | 6.3 | 0.2% | Sep 14, 2026 | A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Impacted is an unknown functi... |
| CVE-2026-90698 | MEDIUM | 5.3 | 0.5% | Sep 14, 2026 | A security flaw has been discovered in memcached 1.6.41/1.6.42/1.6.43. This vulnerability affects the function try_read_... |
| CVE-2026-90697 | MEDIUM | 4.3 | 0.2% | Sep 14, 2026 | A vulnerability was identified in SourceCodester Inventory Management System 1.0. This affects an unknown part of the fi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now