2026 CVE Vulnerabilities
64,734 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-44778 | LOW | 2.9 | 0.5% | Sep 15, 2026 | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Li... |
| CVE-2026-91957 | LOW | 3.1 | 0.3% | Sep 15, 2026 | FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread c... |
| CVE-2026-88621 | LOW | 2.7 | 0.2% | Sep 15, 2026 | OneNav v1.2.4 contains an authenticated arbitrary file deletion vulnerability in the Api::upload() method in class/Api.p... |
| CVE-2026-55775 | LOW | 2.3 | 0.5% | Sep 15, 2026 | OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, OpenBao users granted capabilities o... |
| CVE-2026-55774 | LOW | 2.1 | 0.6% | Sep 15, 2026 | OpenBao is an open source identity-based secrets management system. Prior to 2.5.5, an OpenBao user with access to sys/l... |
| CVE-2026-54450 | LOW | 2.9 | — | Sep 15, 2026 | ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol (MCP) servers. Prior ... |
| CVE-2026-91836 | LOW | 2.8 | 0.3% | Sep 15, 2026 | A flaw has been found in OpenClaw ClawScan up to 0.1.6. This affects an unknown function of the file internal/runner/sta... |
| CVE-2026-91835 | LOW | 2.8 | 0.1% | Sep 15, 2026 | A vulnerability was detected in OpenClaw ClawScan up to 0.1.6. The impacted element is the function IsBinaryFile of the ... |
| CVE-2026-49254 | LOW | 2.9 | — | Sep 15, 2026 | Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.4.4, manager/router/ro... |
| CVE-2026-25827 | LOW | 2.3 | 0.1% | Sep 15, 2026 | An issue was discovered in Keyfactor SignServer before 7.6.0. A number of properties were identified to not have any res... |
| CVE-2026-25825 | LOW | 2.7 | 0.1% | Sep 15, 2026 | An issue was discovered in Keyfactor SignServer before 7.6.0. The output file to which SignerStatusReportWorker logs the... |
| CVE-2026-91926 | LOW | 3.7 | 0.2% | Sep 15, 2026 | A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM target-info parser when a crafted NTLM CHALLENGE messa... |
| CVE-2026-91782 | LOW | 3.3 | 0.1% | Sep 15, 2026 | A vulnerability was detected in GNU Binutils 2.47. Affected by this vulnerability is the function elf_x86_allocate_dynre... |
| CVE-2026-91781 | LOW | 3.3 | 0.1% | Sep 15, 2026 | A security vulnerability has been detected in GNU Binutils 2.47. Affected is the function elf_x86_64_common_section_inde... |
| CVE-2026-91780 | LOW | 3.3 | 0.1% | Sep 15, 2026 | A weakness has been identified in GNU Binutils 2.47. This impacts the function elf_link_add_object_symbols of the file b... |
| CVE-2026-91779 | LOW | 3.3 | 0.1% | Sep 15, 2026 | A security flaw has been discovered in GNU Binutils 2.47. This affects the function _bfd_elf_eh_frame_section_offset of ... |
| CVE-2026-91090 | LOW | 3.9 | 0.1% | Sep 15, 2026 | A vulnerability was determined in GPAC up to f1219cde. The affected element is the function gf_node_activate_ex of the f... |
| CVE-2026-86701 | LOW | 1.8 | 0.1% | Sep 15, 2026 | Android application "ManabiPocket for Parents" contains an improper access control vulnerability in one of its component... |
| CVE-2026-16592 | LOW | 2.7 | 0.2% | Sep 15, 2026 | The WP Directory Kit WordPress plugin through 1.5.7 does not check authorization or listing visibility in one of its sho... |
| CVE-2026-90850 | LOW | 2.4 | 0.2% | Sep 15, 2026 | A vulnerability was detected in PHPGurukul Hostel Management System 3.0. Affected by this issue is some unknown function... |
| CVE-2026-90845 | LOW | 3.5 | 0.2% | Sep 15, 2026 | A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1. This issue affects some unknown processing of the ... |
| CVE-2026-90842 | LOW | 3.7 | 0.2% | Sep 15, 2026 | A weakness has been identified in PHPGurukul Blood Donor Management System 1.0. Affected by this issue is some unknown f... |
| CVE-2026-90835 | LOW | 3.5 | 0.2% | Sep 14, 2026 | A flaw has been found in michaelliao itranswarp up to 2.19. The impacted element is the function Markdown.toHtml of the ... |
| CVE-2026-77191 | LOW | 2.6 | 0.1% | Sep 14, 2026 | An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricte... |
| CVE-2026-75945 | LOW | 2.6 | 0.1% | Sep 14, 2026 | A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued. |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now