2026 CVE Vulnerabilities
64,858 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56881 | HIGH | 8.4 | 0.1% | Sep 15, 2026 | In enable_segment of remap.c, there is a possible permission bypass due to a logic error in the code. This could lead to... |
| CVE-2026-55359 | HIGH | 7.8 | 0.1% | Sep 15, 2026 | In multiple locations, there is a possible permission bypass due to a logic error in the code. This could lead to local ... |
| CVE-2026-55351 | HIGH | 7.8 | 0.1% | Sep 15, 2026 | In VPU, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privi... |
| CVE-2026-55343 | HIGH | 8 | 0.2% | Sep 15, 2026 | In decodeAmr of ImsMediaAudioPlayer.cpp, there is a possible out-of-bounds write due to a missing bounds check. This cou... |
| CVE-2026-55331 | HIGH | 8.8 | 0.3% | Sep 15, 2026 | In IP Multimedia Subsystem, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to... |
| CVE-2026-55323 | HIGH | 7.8 | 0.1% | Sep 15, 2026 | In gf_base_update_finger_base of gf_base.c, there is a possible out-of-bounds write due to a heap buffer overflow. This ... |
| CVE-2026-55318 | HIGH | 8.8 | 0.2% | Sep 15, 2026 | In multiple locations, there is a possible use-after-free due to a race condition. This could lead to remote code execut... |
| CVE-2026-55306 | HIGH | 7.5 | 0.3% | Sep 15, 2026 | In Cellular Modem, there is a possible denial of service due to improper input validation. This could lead to remote den... |
| CVE-2026-55301 | HIGH | 8.4 | 0.1% | Sep 15, 2026 | In Wave6VpuDecFlush of wave6.c, there is a possible out-of-bounds write due to a missing bounds check. This could lead t... |
| CVE-2026-19886 | HIGH | 7.8 | 0.2% | Sep 15, 2026 | OriginLab Origin Viewer OGM File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allow... |
| CVE-2026-19885 | HIGH | 7.8 | 0.2% | Sep 15, 2026 | OriginLab Origin Viewer OGWU File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability al... |
| CVE-2026-19781 | HIGH | 7.8 | 0.2% | Sep 15, 2026 | Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability ... |
| CVE-2026-19774 | HIGH | 7.1 | 0.3% | Sep 15, 2026 | BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent a... |
| CVE-2026-0200 | HIGH | 8.8 | 0.3% | Sep 15, 2026 | In Cellular Modem, there is a possible out-of-bounds write due to a heap buffer overflow. This could lead to remote esca... |
| CVE-2026-0199 | HIGH | 7.8 | 0.1% | Sep 15, 2026 | In gf_ta_test_set_config of gf_ta_test.c, there is a possible out-of-bounds write due to improper input validation. This... |
| CVE-2026-0194 | HIGH | 8.4 | 0.1% | Sep 15, 2026 | In multiple locations, there is a possible permission bypass due to an integer overflow. This could lead to local escala... |
| CVE-2026-0189 | HIGH | 8.4 | 0.1% | Sep 15, 2026 | In ac_init_policy of init.c, there is a possible permission bypass due to a logic error in the code. This could lead to ... |
| CVE-2026-0171 | HIGH | 8.8 | 0.3% | Sep 15, 2026 | In multiple locations, there is a possible out-of-bounds write due to a logic error in the code. This could lead to remo... |
| CVE-2026-0170 | HIGH | 8.8 | 0.3% | Sep 15, 2026 | In Vp9DecodeFrameTag of vp9hwd_headers.cc, there is a possible out-of-bounds write due to a missing bounds check. This c... |
| CVE-2026-0159 | HIGH | 8.8 | 0.3% | Sep 15, 2026 | In Cellular Modem, there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote code... |
| CVE-2026-88765 | HIGH | 8.5 | 0.7% | Sep 15, 2026 | GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 bef... |
| CVE-2026-85234 | HIGH | 7.5 | 0.4% | Sep 15, 2026 | A flaw was found in tftp-hpa. When the `in.tftpd` remap engine processes an inverse remap rule that also aborts with a n... |
| CVE-2026-81899 | HIGH | 7.3 | 0.3% | Sep 15, 2026 | Concrete CMS 9.0.0 to 9.5.2 stored group folder names without sanitization and printed them unescaped on the Members > G... |
| CVE-2026-81898 | HIGH | 7.5 | 0.2% | Sep 15, 2026 | In Concrete CMS below version 9.5.3, the Address attribute's country-less text formatter skipped HTML-escaping, enabling... |
| CVE-2026-61668 | HIGH | 8.1 | 0.2% | Sep 15, 2026 | DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.22, and 9.1... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now