2026 CVE Vulnerabilities
66,321 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-71540 | HIGH | 7.5 | 0.4% | Sep 24, 2026 | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. F... |
| CVE-2026-63645 | HIGH | 7.5 | 0.3% | Sep 24, 2026 | OpenObserve is a cloud-native observability platform. Prior to 0.90.3, OpenObserve registers the /config/runtime endpoin... |
| CVE-2026-61816 | HIGH | 7.5 | 0.4% | Sep 24, 2026 | zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading mess... |
| CVE-2026-61815 | HIGH | 7.2 | 0.2% | Sep 24, 2026 | zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading mess... |
| CVE-2026-61811 | MEDIUM | 6.5 | 0.4% | Sep 24, 2026 | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. F... |
| CVE-2026-61788 | HIGH | 7.4 | 0.3% | Sep 24, 2026 | DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Prior to version 0.22.6, settin... |
| CVE-2026-61784 | MEDIUM | 6.1 | 0.2% | Sep 24, 2026 | xhtml-purifier is a Node.js library to take in raw/unknown/untrusted HTML and output cleaned, purified, trusted HTML. Ve... |
| CVE-2026-61782 | HIGH | 7.5 | 0.4% | Sep 24, 2026 | Rsdoctor is a build analyzer tailored for projects built with Rspack. Prior to version 1.5.16, the default Rsdoctor repo... |
| CVE-2026-61742 | CRITICAL | 9.3 | 0.2% | Sep 24, 2026 | DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite. Versions prior to 0.22.5 expose... |
| CVE-2026-61741 | CRITICAL | 9.3 | 0.3% | Sep 24, 2026 | http4s-scala-xml provides `EntityDecoder[F, scala.xml.Elem]` instances that parse XML message bodies. Prior to versions ... |
| CVE-2026-61732 | CRITICAL | 10 | 1.2% | Sep 24, 2026 | Decepticon is an autonomous hacking agent for red teams. Versions prior to 1.1.17 wrap web crawl results — the output of... |
| CVE-2026-61604 | CRITICAL | 9.3 | 0.3% | Sep 24, 2026 | The ixo Blockchain is a Layer 1 blockchain that runs on both Testnet and Mainnet. Prior to version 8.0.0, the x/bonds mo... |
| CVE-2026-57179 | MEDIUM | 4.2 | 0.2% | Sep 24, 2026 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the partial-pipeline resum... |
| CVE-2026-57178 | HIGH | 7.4 | — | Sep 24, 2026 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the `vk-app` backend accep... |
| CVE-2026-57177 | MEDIUM | 4.3 | — | Sep 24, 2026 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the LoginRadius backend di... |
| CVE-2026-57176 | MEDIUM | 6.8 | — | Sep 24, 2026 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the Vend OAuth2 backend us... |
| CVE-2026-57175 | MEDIUM | 6.4 | — | Sep 24, 2026 | Python Social Auth is a social authentication/registration mechanism. Prior to version 5.0.0, the SAML backend accepted ... |
| CVE-2026-54461 | MEDIUM | 6.5 | 0.3% | Sep 24, 2026 | Habitica is a habit tracker application that treats goals like a role-playing game. From 4.172.1 until 5.48.2, a query p... |
| CVE-2026-97521 | — | — | 0.2% | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: gfs2: fix quota init duplicate scan gfs2_quota_ini... |
| CVE-2026-97520 | HIGH | 7.1 | 0.1% | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: gfs2: move quota_init qc iterator increment Move q... |
| CVE-2026-97519 | — | — | 0.1% | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/xe: Fix null pointer dereference in devcoredump... |
| CVE-2026-97518 | — | — | 0.2% | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: reject duplicate wiphy cipher suite... |
| CVE-2026-97517 | — | — | 0.2% | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: reject beacons with bad HE operation... |
| CVE-2026-97516 | — | — | 0.2% | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: Add NULL check for chip->edcca_th in r... |
| CVE-2026-97515 | — | — | 0.1% | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: i3c: master: svc: Prevent IRQ storm from false SLVS... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now