2026 CVE Vulnerabilities
65,293 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-102005 | MEDIUM | 5.5 | — | Sep 28, 2026 | Wind River VxWorks 7 24.03 through 26.03, a memory leak occurs under specific, non-default configuration states when pro... |
| CVE-2026-101918 | MEDIUM | 5.3 | — | Sep 28, 2026 | PyJWT is a Python implementation of JSON Web Token standards. From 2.0.0a1 until 2.15.0, PyJWT PyJWKClient.get_signing_k... |
| CVE-2026-101917 | MEDIUM | 5.3 | — | Sep 28, 2026 | PyJWT is a Python implementation of JSON Web Token standards. Prior to 2.14.0, PyJWT get_signing_key_from_jwt is affecte... |
| CVE-2026-101916 | HIGH | 7.4 | — | Sep 28, 2026 | @grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1... |
| CVE-2026-101187 | CRITICAL | 9.1 | — | Sep 28, 2026 | A weakness has been identified in Ziroom ZHOME A0101 1.0.1.0. This vulnerability affects the function pop_usb_device of ... |
| CVE-2026-101146 | MEDIUM | 4.3 | — | Sep 28, 2026 | A security flaw has been discovered in Eleveo Quality Management 9.7.0. This issue affects the function UtilsService.cre... |
| CVE-2026-101145 | MEDIUM | 4.3 | — | Sep 28, 2026 | A vulnerability was identified in Eleveo Call Recording Software 9.7.0. This vulnerability affects unknown code of the f... |
| CVE-2026-101144 | MEDIUM | 6.3 | — | Sep 28, 2026 | A vulnerability was determined in Eleveo Call Recording Software 9.7.0. This affects an unknown part of the file /callre... |
| CVE-2026-100392 | HIGH | 7 | — | Sep 28, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, Us... |
| CVE-2026-100371 | HIGH | 8.7 | — | Sep 28, 2026 | InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments. In version 1.7.2, an... |
| CVE-2026-100370 | MEDIUM | 4.7 | — | Sep 28, 2026 | DOMSanitizer is a DOM/SVG/MathML Sanitizer for PHP 7.3+. Prior to version 1.0.15, the isDangerousUrl() method is respons... |
| CVE-2026-96760 | — | — | — | Sep 28, 2026 | Authlib (v1.7.2 and below) contains a signature verification bypass vulnerability. The JsonWebSignature.deserialize_json... |
| CVE-2026-93355 | HIGH | 8.1 | 0.3% | Sep 28, 2026 | LiteLLM contains a weak authentication vulnerability that allows an attacker holding a valid JWT from the configured ide... |
| CVE-2026-87741 | HIGH | 8.8 | — | Sep 28, 2026 | The ConvertPlus plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and inclu... |
| CVE-2026-86950 | HIGH | 8.8 | 0.8% | Sep 28, 2026 | An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 2... |
| CVE-2026-102004 | HIGH | 7.8 | — | Sep 28, 2026 | Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in memory corruption within the memory ma... |
| CVE-2026-101915 | LOW | 3.7 | — | Sep 28, 2026 | @grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.6 and 1... |
| CVE-2026-101914 | MEDIUM | 6.5 | — | Sep 28, 2026 | @grpc/grpc-js implements the core functionality of gRPC purely in JavaScript, without a C++ addon. Prior to 1.13.1 and 1... |
| CVE-2026-101143 | MEDIUM | 4.3 | — | Sep 28, 2026 | A vulnerability was found in Eleveo Quality Management 9.7.0. Affected by this issue is some unknown functionality of th... |
| CVE-2026-101142 | MEDIUM | 6.3 | — | Sep 28, 2026 | A vulnerability has been found in Eleveo Quality Management 9.7.0. Affected by this vulnerability is an unknown function... |
| CVE-2026-101141 | LOW | 3.5 | — | Sep 28, 2026 | A flaw has been found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/audi... |
| CVE-2026-97686 | MEDIUM | 5.5 | — | Sep 28, 2026 | Wind River VxWorks 7 prior to 26.09, specific system call arguments can result in the IPNET subsystem failing to properl... |
| CVE-2026-97023 | HIGH | 7.1 | — | Sep 28, 2026 | A path traversal vulnerability in Flatpak's handling of the export/bin directory during app deployment allows a maliciou... |
| CVE-2026-84894 | — | — | — | Sep 28, 2026 | In moxygen before commit 004123dd24c3, MoQSession::dataStreamReadLoop keeps using a stream read handle after reading a F... |
| CVE-2026-13018 | MEDIUM | 4.3 | — | Sep 28, 2026 | Insufficient validation of untrusted input in Codecs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now