2026 CVE Vulnerabilities
65,279 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-102281 | HIGH | 7.5 | — | Sep 28, 2026 | Nest is a framework for building scalable Node.js server-side applications. Prior to 11.2.4 and 12.0.2, a single message... |
| CVE-2026-101205 | MEDIUM | 6.3 | — | Sep 28, 2026 | A vulnerability was determined in FastStone Image Viewer up to 8.3. This impacts an unknown function of the component PC... |
| CVE-2026-101204 | MEDIUM | 6.3 | — | Sep 28, 2026 | A vulnerability was found in FastStone Image Viewer up to 8.3. This affects an unknown function of the file FSViewer.exe... |
| CVE-2026-101203 | MEDIUM | 6.3 | — | Sep 28, 2026 | A vulnerability has been found in FastStone Image Viewer up to 8.3. The impacted element is an unknown function of the c... |
| CVE-2026-101202 | MEDIUM | 6.3 | — | Sep 28, 2026 | A flaw has been found in FastStone Image Viewer up to 8.3. The affected element is an unknown function of the component ... |
| CVE-2026-101188 | HIGH | 8.3 | — | Sep 28, 2026 | A security vulnerability has been detected in Netcore POWER13 2.0.240730.162638. This issue affects the function routerd... |
| CVE-2026-101093 | MEDIUM | 5.4 | — | Sep 28, 2026 | Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in admin.users.php that allows attackers to de... |
| CVE-2026-101092 | MEDIUM | 5.3 | — | Sep 28, 2026 | SiYuan before v3.8.4 fails to enforce publish-access checks in the getCurrentAttrViewImages endpoint, allowing publish r... |
| CVE-2026-101091 | HIGH | 7.1 | — | Sep 28, 2026 | SiYuan versions before v3.8.4 fail to properly validate SQL statements in block query embed blocks executed against siyu... |
| CVE-2026-97027 | LOW | 3.6 | — | Sep 28, 2026 | Flatpak passes through arbitrary vendor-extension keys unmodified when exporting an application's Desktop Entry (.deskto... |
| CVE-2026-97026 | LOW | 3.9 | — | Sep 28, 2026 | Flatpak creates temporary child repository directories under the user cache with world-writable permissions (0777). On m... |
| CVE-2026-97025 | LOW | 3.2 | — | Sep 28, 2026 | Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cac... |
| CVE-2026-91096 | — | — | — | Sep 28, 2026 | In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::terminateSessionStreams (WebTransportImpl::destr... |
| CVE-2026-91095 | — | — | — | Sep 28, 2026 | In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::... |
| CVE-2026-84895 | — | — | — | Sep 28, 2026 | In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calli... |
| CVE-2026-18416 | LOW | 3.7 | — | Sep 28, 2026 | The CoAP link-format helper match_path_uri() in subsys/net/lib/coap/coap_link_format.c compares a registered resource pa... |
| CVE-2026-18415 | MEDIUM | 6.3 | — | Sep 28, 2026 | ieee802154_send() in subsys/net/l2/ieee802154/ieee802154.c copies the outgoing packet into a single fixed 125-byte trans... |
| CVE-2026-18414 | HIGH | 7.8 | — | Sep 28, 2026 | The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size fi... |
| CVE-2026-18413 | HIGH | 7.8 | — | Sep 28, 2026 | The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size fi... |
| CVE-2026-16513 | HIGH | 7.8 | — | Sep 28, 2026 | The userspace verifier z_vrfy_rtio_sqe_copy_in_get_handles() in subsys/rtio/rtio_syscalls.c (subsys/rtio/rtio_handlers.c... |
| CVE-2026-102279 | LOW | 3.1 | — | Sep 28, 2026 | Laravel is a web application framework. Prior to 12.69.0 and 13.30.0, Laravel exception debug pages with APP_DEBUG=true ... |
| CVE-2026-102278 | HIGH | 7.5 | — | Sep 28, 2026 | The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3... |
| CVE-2026-102277 | MEDIUM | 5.3 | — | Sep 28, 2026 | The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3... |
| CVE-2026-102276 | HIGH | 7.5 | — | Sep 28, 2026 | The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3... |
| CVE-2026-102275 | MEDIUM | 6.5 | — | Sep 28, 2026 | PyJWT is a Python implementation of JSON Web Token standards. From 2.1.0 until 2.15.0, PyJWT OKPAlgorithm.from_jwk in j... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now