2026 CVE Vulnerabilities
64,858 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-61544 | HIGH | 8.2 | 0.2% | Sep 15, 2026 | libp2p-rust is the official Rust language implementation of the libp2p networking stack. Prior to 0.13.1, libp2p-quic co... |
| CVE-2026-51134 | HIGH | 7.5 | 1.9% | Sep 15, 2026 | The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' paramete... |
| CVE-2026-18424 | HIGH | 7.1 | 0.3% | Sep 15, 2026 | Concrete CMS 9.0.0 to 9.5.2 is vulnerable to Server-Side Request Forgery iremote file import via cross-port reuse of a h... |
| CVE-2026-18423 | HIGH | 7.1 | 0.3% | Sep 15, 2026 | Concrete CMS 9.0.0 through 9.5.2 is vulnerable to Insecure direct object reference (IDOR) in the Express saved search p... |
| CVE-2026-13327 | HIGH | 8.3 | 0.1% | Sep 15, 2026 | Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier all... |
| CVE-2026-92180 | HIGH | 7.8 | 0.1% | Sep 15, 2026 | pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vul... |
| CVE-2026-92179 | HIGH | 7.8 | 0.2% | Sep 15, 2026 | pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allo... |
| CVE-2026-92178 | HIGH | 7.8 | 0.2% | Sep 15, 2026 | pdfforge PDF Architect PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows... |
| CVE-2026-92177 | HIGH | 7.8 | 0.2% | Sep 15, 2026 | pdfforge PDF Architect PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allo... |
| CVE-2026-92176 | HIGH | 7.8 | 0.2% | Sep 15, 2026 | pdfforge PDF Architect App Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remo... |
| CVE-2026-82189 | HIGH | 8.7 | 0.3% | Sep 15, 2026 | Joomla Extension - j2commerce.com - Any order can be marked Failed by anyone in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0... |
| CVE-2026-81568 | HIGH | 8.7 | 0.3% | Sep 15, 2026 | Joomla Extension - j2commerce.com - Arbitrary file read via `task=download` in J2Store 1.0.0-3.3.2, 4.0.0-4.0.22, 4.1.0-... |
| CVE-2026-81567 | HIGH | 8.7 | 0.2% | Sep 15, 2026 | Joomla Extension - j2commerce.com - Unauthenticated blind SQL injection in the storefront product list in J2Store 1.0.0-... |
| CVE-2026-79411 | HIGH | 8.8 | 0.3% | Sep 15, 2026 | Incorrect privilege assignment in the admin user-management component of Webkul Bagisto 2.4.9 allows an authenticated ba... |
| CVE-2026-79410 | HIGH | 8.1 | 0.3% | Sep 15, 2026 | Improper validation of the quantity parameter in the add-to-cart path of Webkul Bagisto v2.4.9 allows authenticated atta... |
| CVE-2026-78081 | HIGH | 7.1 | 0.2% | Sep 15, 2026 | Joomla Extension - j2commerce.com - Missing CSRF protection on cart, checkout and myprofile controllers in J2Store 1.0.0... |
| CVE-2026-69213 | HIGH | 7.5 | 0.4% | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, Ember HTTP/2 serializes outbound frames t... |
| CVE-2026-69209 | HIGH | 7.5 | 0.4% | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, The shared WebSocket decoder permits unbo... |
| CVE-2026-69208 | HIGH | 7.5 | 0.4% | Sep 15, 2026 | Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1.0.0-M47, the DigestAuth server middleware removes ... |
| CVE-2026-58766 | HIGH | 7.8 | 0.1% | Sep 15, 2026 | In multiple functions of arm-smmu-v3.c, there is a possible escalation of privilege due to a logic error in the code. Th... |
| CVE-2026-58744 | HIGH | 7.8 | 0.1% | Sep 15, 2026 | In multiple locations, there is a possible escalation of privilege due to improper input validation. This could lead to ... |
| CVE-2026-58734 | HIGH | 7 | 0.1% | Sep 15, 2026 | In google_mba_recv_msg of google_mba_poll.c, there is a possible out-of-bounds write due to a race condition. This could... |
| CVE-2026-58728 | HIGH | 7 | 0.1% | Sep 15, 2026 | In ARM64_TLBI of mmu.h, there is a possible memory corruption due to a race condition. This could lead to local escalati... |
| CVE-2026-58724 | HIGH | 7 | 0.1% | Sep 15, 2026 | In multiple locations, there is a possible use-after-free due to a race condition. This could lead to local escalation o... |
| CVE-2026-58710 | HIGH | 8.8 | 0.3% | Sep 15, 2026 | In DecodeFilmGrainParams of film_grain_dec.cc, there is a possible out-of-bounds write due to a missing bounds check. Th... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now