2026 CVE Vulnerabilities
66,372 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93782 | HIGH | 7.8 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: vhost-scsi: flush backend after device ioctls vhos... |
| CVE-2026-93781 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: scsi: core: Do not block on tag allocation in scsi_... |
| CVE-2026-93545 | MEDIUM | 6.5 | — | Sep 24, 2026 | An out-of-bounds read in libXi's XListInputDevices() in libXi before 1.8.4 could be used by malicious X servers to crash... |
| CVE-2026-93544 | MEDIUM | 6.5 | — | Sep 24, 2026 | An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in libXi before 1.8.4 can be used by a malicious X serv... |
| CVE-2026-93543 | HIGH | 7.4 | — | Sep 24, 2026 | An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8.4 could be used by malicious X servers to crash an... |
| CVE-2026-93542 | MEDIUM | 6.5 | — | Sep 24, 2026 | An out-of-bounds read in libXi's XI2 class parsing via size_classes() and copy_classes() in libXi before 1.8.4 could be ... |
| CVE-2026-93288 | HIGH | 7.8 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nfnetlink_log: wait for rcu grace period... |
| CVE-2026-93287 | HIGH | 7.8 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: i2c: smbus: reject oversized block transfers in the... |
| CVE-2026-93286 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: net: appletalk: fix NULL pointer dereference in aar... |
| CVE-2026-93285 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: f2fs: embed f2fs_gc_kthread in f2fs_sb_info Instea... |
| CVE-2026-93284 | HIGH | 8.8 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: drm/pagemap: dma-unmap pages before handling migrat... |
| CVE-2026-91161 | MEDIUM | 6.4 | 0.2% | Sep 24, 2026 | OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior to 0.23.5, the GET /api/sessions/{sessionId}/grou... |
| CVE-2026-91160 | HIGH | 8.2 | 0.3% | Sep 24, 2026 | OpenWA is a free, open source, self-hosted WhatsApp API gateway. Prior to 0.23.5, the /events WebSocket gateway delivers... |
| CVE-2026-91134 | MEDIUM | 5.4 | — | Sep 24, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the Discourse post... |
| CVE-2026-91133 | MEDIUM | 6.5 | — | Sep 24, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, authenticated user... |
| CVE-2026-91132 | MEDIUM | 4.3 | — | Sep 24, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, sites using wildca... |
| CVE-2026-91123 | HIGH | 7.2 | — | Sep 24, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the iframe src tra... |
| CVE-2026-91122 | HIGH | 8.7 | — | Sep 24, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the video placehol... |
| CVE-2026-88390 | HIGH | 7.7 | — | Sep 24, 2026 | An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0) allows crafted Java... |
| CVE-2026-88385 | — | — | — | Sep 24, 2026 | Mini-XML 4.0.5 contains a memory leak vulnerability in mxml_load_data() during malformed XML parsing. Specially crafted ... |
| CVE-2026-88384 | MEDIUM | 5.5 | — | Sep 24, 2026 | OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribute parsing path. A specially crafted EXR file conta... |
| CVE-2026-88383 | — | — | — | Sep 24, 2026 | libical 4.0.6 contains an incompatible function pointer in icalparameter_string_to_kind(). When parsing iCalendar data c... |
| CVE-2026-88382 | HIGH | 7.5 | — | Sep 24, 2026 | hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory allocation vulnerability in its RESP aggregate pars... |
| CVE-2026-88378 | CRITICAL | 9.8 | — | Sep 24, 2026 | QuickJS commit 04be24600 contains a heap out-of-bounds write condition in JS_ReadFunctionTag(). |
| CVE-2026-88377 | MEDIUM | 6.2 | — | Sep 24, 2026 | Bento4 1.6.0.0 contains an integer underflow vulnerability in the avcC and hvcC configuration atom parsers. A specially ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now