2026 CVE Vulnerabilities
64,868 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-79725 | MEDIUM | 6.5 | 0.3% | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to imprope... |
| CVE-2026-79723 | MEDIUM | 5 | 0.2% | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to... |
| CVE-2026-79590 | MEDIUM | 6.5 | 0.3% | Sep 10, 2026 | A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a ... |
| CVE-2026-71642 | MEDIUM | 4 | 0.1% | Sep 10, 2026 | An issue in ZJU-FAST-Lab EGO-Planner-v2 All versions up to commit 5c99a95880401e2599638d567abc0e240396cb42 allows an att... |
| CVE-2026-54054 | MEDIUM | 6.5 | 0.3% | Sep 10, 2026 | Transmute is a free, open-source, self-hosted file conversion and compression tool. Prior to version 1.3.0, Transmute's ... |
| CVE-2026-49838 | MEDIUM | 5.9 | 0.3% | Sep 10, 2026 | GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.... |
| CVE-2026-49837 | MEDIUM | 5.9 | 0.3% | Sep 10, 2026 | GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Versions prior to 4... |
| CVE-2026-49836 | MEDIUM | 4.6 | 0.2% | Sep 10, 2026 | psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to version 1.17.1, `SmartObject.save()` ... |
| CVE-2026-45767 | MEDIUM | 4.4 | 0.3% | Sep 10, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2026-36392 | MEDIUM | 5.4 | 0.2% | Sep 10, 2026 | FairSketch Rise CRM Version 3.9.6 is vulnerable to Cross Site Scripting (XSS). An authenticated administrator can inject... |
| CVE-2026-9667 | MEDIUM | 5.3 | 0.3% | Sep 10, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) that could allow a rem... |
| CVE-2026-9225 | MEDIUM | 6.5 | 0.2% | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an authenticated attacker to access sensitive files belonging... |
| CVE-2026-89089 | MEDIUM | 6.5 | 0.2% | Sep 10, 2026 | A SQL injection vulnerability exists in the JasperReports-based reporting feature of multiple versions of OpenNMS Meridi... |
| CVE-2026-76653 | MEDIUM | 5.3 | 0.3% | Sep 10, 2026 | A missing authentication vulnerability in the VPN configuration management has been identified in Archer MR600 (v2, v3 &... |
| CVE-2026-76652 | MEDIUM | 4.8 | 0.5% | Sep 10, 2026 | An authenticated directory traversal vulnerability in file upload functionality has been identified in Archer MR600 (v2,... |
| CVE-2026-45752 | MEDIUM | 5.9 | 0.5% | Sep 10, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. St... |
| CVE-2026-45751 | MEDIUM | 5.9 | 0.5% | Sep 10, 2026 | Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Pr... |
| CVE-2026-3096 | MEDIUM | 4.7 | 0.2% | Sep 10, 2026 | The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the origina... |
| CVE-2026-19596 | MEDIUM | 5.9 | 0.2% | Sep 10, 2026 | An XML External Entity (XXE) vulnerability exists in the XML collector of multiple versions of OpenNMS Meridian and Hori... |
| CVE-2026-88061 | MEDIUM | 5.8 | 0.2% | Sep 10, 2026 | career-ops is an open-source AI-assisted job search and application management tool. Prior to 0.8.0, the career-ops loca... |
| CVE-2026-84432 | MEDIUM | 5.3 | — | Sep 10, 2026 | Concrete CMS 9 through 9.5.2 did not validate an anti-CSRF token in the Boards custom slot dialog controller (concrete/... |
| CVE-2026-9338 | MEDIUM | 5.3 | 0.3% | Sep 10, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a denial of service, caused by sending a specially-crafte... |
| CVE-2026-88059 | MEDIUM | 4 | 0.3% | Sep 10, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-88057 | MEDIUM | 5.3 | 0.4% | Sep 10, 2026 | Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other... |
| CVE-2026-88035 | MEDIUM | 5.5 | 0.1% | Sep 10, 2026 | A size check in the client-side authentication path of the MongoDB C Driver can wrap around, so an unusually large user-... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now