2026 CVE Vulnerabilities
66,315 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53493 | MEDIUM | 6.9 | — | Sep 25, 2026 | containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI... |
| CVE-2026-85082 | HIGH | 8.5 | 0.1% | Sep 25, 2026 | Root Browser Classic 3.3.0 passes the path of a selected SQLite database to an operating-system shell without safely sep... |
| CVE-2026-84283 | MEDIUM | 6.8 | 0.1% | Sep 25, 2026 | Secure Folder 1.2 stores files selected for its password-protected vault as unencrypted files in the Android shared-stor... |
| CVE-2026-97387 | — | — | — | Sep 24, 2026 | Rejected reason: This CVE is a duplicate of another CVE. |
| CVE-2026-97230 | CRITICAL | 9.8 | 0.1% | Sep 24, 2026 | IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated U... |
| CVE-2026-97636 | MEDIUM | 6.5 | 0.2% | Sep 24, 2026 | Apache Airflow HashiCorp provider: the HashiCorp Vault secrets backend's team-scope guard can be bypassed with a user-co... |
| CVE-2026-87722 | HIGH | 8.7 | 0.3% | Sep 24, 2026 | Uncontrolled Resource Consumption (CWE-400 / CWE-1333) in regex search query predicates (such as RegexProjectPredicate, ... |
| CVE-2026-87721 | HIGH | 8.7 | 0.3% | Sep 24, 2026 | Uncontrolled Resource Consumption (CWE-400 / CWE-407) in the ANTLR 3 search query parser (QueryParser / Query.g) in Gerr... |
| CVE-2026-87720 | HIGH | 7.6 | 0.3% | Sep 24, 2026 | Incorrect Authorization (CWE-863) in project name normalization (ProjectUtil.stripGitSuffix) and ProjectCache eviction l... |
| CVE-2026-85491 | HIGH | 8.8 | 0.4% | Sep 24, 2026 | Catalyst::Seal versions before 0.03 for Perl allow one request to disable a path or route a later one past an authorizat... |
| CVE-2026-97368 | MEDIUM | 6.3 | — | Sep 24, 2026 | A weakness has been identified in chillzhuang SpringBlade up to 5.0.2. This affects the function UserServiceImpl.userInf... |
| CVE-2026-97366 | MEDIUM | 6.3 | 1.2% | Sep 24, 2026 | A security flaw has been discovered in jhen0409 react-native-debugger up to 0.14.0. The impacted element is the function... |
| CVE-2026-95699 | CRITICAL | 9.6 | 0.3% | Sep 24, 2026 | Prior to 9/18/2026, the iSteamX mobile application's AWS policy could grant authenticated users access to wildcard MQTT ... |
| CVE-2026-93353 | LOW | 3.1 | 0.3% | Sep 24, 2026 | copyparty contains a volume restriction bypass vulnerability in its SFTP front end that allows authenticated SFTP users ... |
| CVE-2026-88388 | HIGH | 7.5 | 0.2% | Sep 24, 2026 | Espruino 2v29 (commit bffc6d0) contains a stack-based buffer overflow vulnerability in the JavaScript error stack-trace ... |
| CVE-2026-88387 | MEDIUM | 5.5 | — | Sep 24, 2026 | LibRaw 0.22.0 contains an incorrect numeric conversion vulnerability in LibRaw::parse_tiff_ifd() when processing TIFF ta... |
| CVE-2026-88386 | MEDIUM | 5.5 | 0.1% | Sep 24, 2026 | libsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_readf() while parsing WAV fmt chunks. A spec... |
| CVE-2026-87118 | MEDIUM | 5.7 | 0.2% | Sep 24, 2026 | The Botslab G980H dash camera firmware contains an out of bounds write vulnerability in its command processing functiona... |
| CVE-2026-84403 | MEDIUM | 6.2 | 0.1% | Sep 24, 2026 | The Botslab G980H dash camera firmware does not require authenticated pairing or client binding before permitting access... |
| CVE-2026-82716 | MEDIUM | 4.6 | 0.2% | Sep 24, 2026 | The Botslab G980H dash camera firmware includes sensitive configuration information, including WiFi credentials, in diag... |
| CVE-2026-82708 | MEDIUM | 6.5 | 0.2% | Sep 24, 2026 | The Botslab G980H dash camera firmware contains a path traversal vulnerability in its HTTP server. An attacker with acce... |
| CVE-2026-82585 | MEDIUM | 6.5 | 0.1% | Sep 24, 2026 | The Botslab G980H dash camera firmware transmits sensitive information over unencrypted HTTP and RTSP connections. An at... |
| CVE-2026-81630 | HIGH | 8.1 | 0.2% | Sep 24, 2026 | The Botslab G980H dash camera firmware does not adequately verify the authenticity of firmware updates. The update proce... |
| CVE-2026-79959 | MEDIUM | 6.8 | 0.2% | Sep 24, 2026 | The Botslab G980H dash camera firmware contains a hard-coded root account password that cannot be changed by the user. A... |
| CVE-2026-75558 | MEDIUM | 5.3 | 0.2% | Sep 24, 2026 | The Botslab G980H dash camera firmware uses a hard-coded cryptographic key and initialization vector to protect WiFi cre... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now