2026 CVE Vulnerabilities
64,858 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-89050 | MEDIUM | 4.3 | 0.1% | Sep 13, 2026 | The Quads Ads Manager for Google AdSense WordPress plugin before 3.0.5 does not verify payment completion with the confi... |
| CVE-2026-36989 | MEDIUM | 5.8 | 0.2% | Sep 13, 2026 | A SQL Injection vulnerability exists in LuxSoft LuxCal through 5.3.4L via rssfeed.php and common/retrieve.php. |
| CVE-2026-90583 | MEDIUM | 4.3 | 0.3% | Sep 13, 2026 | A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected ... |
| CVE-2026-90582 | MEDIUM | 5.3 | 0.4% | Sep 13, 2026 | A vulnerability was identified in evanchiu serverless-todo 1.0.3/2.0.0. Impacted is the function saveTodos of the file s... |
| CVE-2026-90581 | MEDIUM | 6.3 | 0.2% | Sep 13, 2026 | A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpd... |
| CVE-2026-90580 | MEDIUM | 6.3 | 0.2% | Sep 13, 2026 | A vulnerability was found in FlowiseAI Flowise up to 3.0.2. This vulnerability affects the function axios.post of the fi... |
| CVE-2026-29812 | MEDIUM | 4.3 | 0.2% | Sep 13, 2026 | CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list. |
| CVE-2026-29810 | MEDIUM | 4.3 | 0.3% | Sep 13, 2026 | CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic. |
| CVE-2026-90578 | MEDIUM | 5.3 | 0.2% | Sep 13, 2026 | A flaw has been found in GPAC up to f1219cde. Affected by this issue is the function gf_list_count of the file utils/lis... |
| CVE-2026-90577 | MEDIUM | 5.3 | 0.2% | Sep 13, 2026 | A vulnerability was detected in GPAC up to f1219cde. Affected by this vulnerability is the function gf_node_get_field of... |
| CVE-2026-90574 | MEDIUM | 6.3 | 0.3% | Sep 13, 2026 | A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of ... |
| CVE-2026-90572 | MEDIUM | 4.7 | 0.4% | Sep 13, 2026 | A vulnerability was determined in davenardella snap7 up to 1.4.3. The affected element is the function TSnap7MicroClient... |
| CVE-2026-90571 | MEDIUM | 4.3 | 0.3% | Sep 13, 2026 | A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown functio... |
| CVE-2026-90565 | MEDIUM | 5.3 | 0.5% | Sep 13, 2026 | A security flaw has been discovered in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e0... |
| CVE-2026-90527 | MEDIUM | 4.3 | 0.3% | Sep 13, 2026 | A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admi... |
| CVE-2026-90525 | MEDIUM | 6.3 | 0.3% | Sep 13, 2026 | A weakness has been identified in itsourcecode Sales and Inventory System 1.0. This affects an unknown function of the f... |
| CVE-2026-90782 | MEDIUM | 5.3 | 0.3% | Sep 13, 2026 | S2OPC through 1.7.3 contains a null pointer dereference in msg_subscription_publish_bs__alloc_notification_message_items... |
| CVE-2026-90781 | MEDIUM | 4.4 | 0.2% | Sep 13, 2026 | alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __snd_ctl_ascii_elem_id_parse() function that writes o... |
| CVE-2026-90521 | MEDIUM | 6.3 | 0.4% | Sep 13, 2026 | A vulnerability was found in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. Th... |
| CVE-2026-90520 | MEDIUM | 6.3 | 0.4% | Sep 13, 2026 | A vulnerability has been found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa6... |
| CVE-2026-90519 | MEDIUM | 6.3 | 0.2% | Sep 13, 2026 | A weakness has been identified in PHPGurukul Bank Locker Management System 1.0. Affected is an unknown function of the f... |
| CVE-2026-90775 | MEDIUM | 6.5 | 0.6% | Sep 13, 2026 | PostGIS address_standardizer through 3.7.0 fails to validate the Weight parameter from caller-supplied rules tables befo... |
| CVE-2026-90518 | MEDIUM | 6.3 | 0.2% | Sep 13, 2026 | A security flaw has been discovered in PHPGurukul Bank Locker Management System 1.0. This impacts an unknown function of... |
| CVE-2026-90517 | MEDIUM | 5.3 | 0.3% | Sep 13, 2026 | A vulnerability was identified in PHPGurukul Bank Locker Management System 1.0. This affects an unknown function of the ... |
| CVE-2026-90767 | MEDIUM | 6.5 | 0.2% | Sep 13, 2026 | Froxlor before 2.3.12 fails to properly validate multi-line SSH public keys in the SshKeys::add() endpoint, allowing cus... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now