2026 CVE Vulnerabilities
65,293 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-97025 | LOW | 3.2 | — | Sep 28, 2026 | Flatpak writes the OCI repository authentication token with world-readable permissions (0644) in the system-helper's cac... |
| CVE-2026-91096 | — | — | — | Sep 28, 2026 | In proxygen from v2024.10.28.00 until v2026.09.28.00, WebTransportImpl::terminateSessionStreams (WebTransportImpl::destr... |
| CVE-2026-91095 | — | — | — | Sep 28, 2026 | In proxygen from v2024.10.28.00 until v2026.09.28.00, the HTTPTransaction::onWebTransportUniStream and HTTPTransaction::... |
| CVE-2026-84895 | — | — | — | Sep 28, 2026 | In proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calli... |
| CVE-2026-18416 | LOW | 3.7 | — | Sep 28, 2026 | The CoAP link-format helper match_path_uri() in subsys/net/lib/coap/coap_link_format.c compares a registered resource pa... |
| CVE-2026-18415 | MEDIUM | 6.3 | — | Sep 28, 2026 | ieee802154_send() in subsys/net/l2/ieee802154/ieee802154.c copies the outgoing packet into a single fixed 125-byte trans... |
| CVE-2026-18414 | HIGH | 7.8 | — | Sep 28, 2026 | The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size fi... |
| CVE-2026-18413 | HIGH | 7.8 | — | Sep 28, 2026 | The ADC API requires each driver to reject a sampling sequence whose destination buffer is too small: the buffer_size fi... |
| CVE-2026-16513 | HIGH | 7.8 | — | Sep 28, 2026 | The userspace verifier z_vrfy_rtio_sqe_copy_in_get_handles() in subsys/rtio/rtio_syscalls.c (subsys/rtio/rtio_handlers.c... |
| CVE-2026-102279 | LOW | 3.1 | 0.2% | Sep 28, 2026 | Laravel is a web application framework. Prior to 12.69.0 and 13.30.0, Laravel exception debug pages with APP_DEBUG=true ... |
| CVE-2026-102278 | HIGH | 7.5 | — | Sep 28, 2026 | The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.20, 2.1.6, 3... |
| CVE-2026-102277 | MEDIUM | 5.3 | — | Sep 28, 2026 | The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.21, 2.1.7, 3... |
| CVE-2026-102276 | HIGH | 7.5 | — | Sep 28, 2026 | The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.19, 2.1.5, 3... |
| CVE-2026-102275 | MEDIUM | 6.5 | — | Sep 28, 2026 | PyJWT is a Python implementation of JSON Web Token standards. From 2.1.0 until 2.15.0, PyJWT OKPAlgorithm.from_jwk in j... |
| CVE-2026-102274 | MEDIUM | 5.9 | — | Sep 28, 2026 | PyJWT is a Python implementation of JSON Web Token standards. From 2.9.0 until 2.14.0, PyJWKSet does not catch the plain... |
| CVE-2026-102273 | HIGH | 7.4 | — | Sep 28, 2026 | PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key ... |
| CVE-2026-102272 | HIGH | 7.4 | 0.2% | Sep 28, 2026 | PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.prepare_key in jwt... |
| CVE-2026-102271 | HIGH | 7.4 | — | Sep 28, 2026 | PyJWT is a Python implementation of JSON Web Token standards. From 2.4.0 until 2.14.0, PyJWT HMACAlgorithm.prepare_key i... |
| CVE-2026-102270 | MEDIUM | 4.4 | — | Sep 28, 2026 | PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT is_pem_format is affected because l... |
| CVE-2026-102269 | MEDIUM | 4.8 | — | Sep 28, 2026 | PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT signature segment is affected becau... |
| CVE-2026-102268 | CRITICAL | 9.1 | — | Sep 28, 2026 | PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, is_pem_format in jwt/utils.py is affected... |
| CVE-2026-102267 | HIGH | 7.4 | — | Sep 28, 2026 | PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT PyJWKClient is affected because red... |
| CVE-2026-102266 | HIGH | 7.4 | — | Sep 28, 2026 | PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, HMACAlgorithm.from_jwk is affect... |
| CVE-2026-102265 | MEDIUM | 5.3 | — | Sep 28, 2026 | PyJWT is a Python implementation of JSON Web Token standards. From 2.13.0 until 2.14.0, PyJWS._load in jwt/api_jws.py is... |
| CVE-2026-102006 | MEDIUM | 5.5 | — | Sep 28, 2026 | In Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the process management subsystem fa... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now