2026 CVE Vulnerabilities
64,909 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-90444 | HIGH | 8.7 | 0.2% | Sep 11, 2026 | A file-transfer interface that requires valid credentials accepts attacker-controlled filenames without restricting shel... |
| CVE-2026-54241 | HIGH | 7.4 | 0.2% | Sep 11, 2026 | libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic... |
| CVE-2026-54240 | HIGH | 7.4 | 0.2% | Sep 11, 2026 | libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic... |
| CVE-2026-50013 | HIGH | 7.5 | 0.3% | Sep 11, 2026 | Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `Add... |
| CVE-2026-49846 | HIGH | 7.5 | 0.3% | Sep 11, 2026 | libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP re... |
| CVE-2026-44715 | HIGH | 8.7 | 0.4% | Sep 11, 2026 | OpenMRS is an open source electronic medical record system platform. Prior to versions 1.23.0 and 2.10.0, an authenticat... |
| CVE-2026-81907 | HIGH | 7.1 | 0.3% | Sep 11, 2026 | Concrete CMS 9.5.2 and below is vulnerable to Cross-Site Request Forgery (CSRF) in the Express "Clear Entries" function ... |
| CVE-2026-54174 | HIGH | 8.3 | 0.1% | Sep 11, 2026 | melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to me... |
| CVE-2026-54166 | HIGH | 7.1 | 0.3% | Sep 11, 2026 | Shelf is a platform for tracking physical assets. Prior to version 1.20.3, authenticated users with the `asset:import` p... |
| CVE-2026-49464 | HIGH | 8.1 | 0.2% | Sep 11, 2026 | NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, custom... |
| CVE-2026-47773 | HIGH | 7.2 | 0.1% | Sep 11, 2026 | ArduinoBLE enables Bluetooth Low Energy connectivity on certain Arduino models. Versions prior to 2.0.2 contain a missin... |
| CVE-2026-89771 | HIGH | 7.8 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Fix subbuf resize race with ring buffe... |
| CVE-2026-89769 | HIGH | 7.4 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: clocksource/drivers/nxp-pit: Fix IRQ leak on cpuhp_... |
| CVE-2026-89767 | HIGH | 7.8 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: ovl: fix double end_creating() on the casefold-mism... |
| CVE-2026-89764 | HIGH | 7.8 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: rust: devres: fix race between concurrent revokers ... |
| CVE-2026-89763 | HIGH | 7.8 | 0.1% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: Fix TPM teardown ordering trusted_t... |
| CVE-2026-89762 | HIGH | 7.8 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix cred UAF caused by begin_current_labe... |
| CVE-2026-89761 | HIGH | 7.8 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: apparmor: fix out-of-bounds write when null termina... |
| CVE-2026-89760 | HIGH | 7.8 | 0.1% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm, swap: don't free a hibernation slot that is in ... |
| CVE-2026-89758 | HIGH | 7.8 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/mempolicy: skip non-present PMDs when queueing f... |
| CVE-2026-89755 | HIGH | 7.8 | 0.1% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/migrate_device: clear stale mapping after freein... |
| CVE-2026-89754 | HIGH | 7.8 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: mm/pagewalk: fix stale walk->action escaping walk_p... |
| CVE-2026-89750 | HIGH | 7.8 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: tracing/user_events: Clear copied tracing state bef... |
| CVE-2026-89748 | HIGH | 7.8 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: tracing: Fix retry exhaustion in simple ring buffer... |
| CVE-2026-89747 | HIGH | 7.8 | 0.2% | Sep 11, 2026 | In the Linux kernel, the following vulnerability has been resolved: tracing: Fix use-after-free in trace_pipe read on s... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now