2026 CVE Vulnerabilities
64,751 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93374 | CRITICAL | 9.6 | 0.4% | Sep 17, 2026 | Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially ex... |
| CVE-2026-93373 | CRITICAL | 9.6 | 0.3% | Sep 17, 2026 | Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code... |
| CVE-2026-93372 | CRITICAL | 9.6 | 0.4% | Sep 17, 2026 | Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to execute arbi... |
| CVE-2026-54501 | CRITICAL | 9.4 | 1.8% | Sep 17, 2026 | Browsertrix is a high-fidelity, browser-based crawling service for web archiving that can be self-hosted or used through... |
| CVE-2026-54460 | CRITICAL | 9.8 | 0.7% | Sep 17, 2026 | OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to 1.1... |
| CVE-2026-54237 | CRITICAL | 9.3 | 0.8% | Sep 17, 2026 | Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /instal... |
| CVE-2026-45143 | CRITICAL | 9 | 0.5% | Sep 17, 2026 | Chamilo LMS is an open-source learning management system. From 2.0.0 through at least 2.1.0, Chamilo LMS stores private ... |
| CVE-2026-45140 | CRITICAL | 9.8 | 1.3% | Sep 17, 2026 | Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote a... |
| CVE-2026-54752 | CRITICAL | 9.6 | 0.7% | Sep 17, 2026 | NetBox Device Type Library is a collection of community-sourced device type definitions for import into NetBox. The vali... |
| CVE-2026-54627 | CRITICAL | 9.8 | 0.4% | Sep 17, 2026 | SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. I... |
| CVE-2026-54626 | CRITICAL | 9.8 | 0.8% | Sep 17, 2026 | SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. I... |
| CVE-2026-54618 | CRITICAL | 9.4 | 0.6% | Sep 17, 2026 | Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Prior to 0.2.0, /oauth/authorize issues an authoriza... |
| CVE-2026-54617 | CRITICAL | 9.8 | 1.1% | Sep 17, 2026 | GravitLauncher is an open-source Minecraft launcher based on sashok724's v3. Prior to 5.7.12, an unauthenticated remote ... |
| CVE-2026-47252 | CRITICAL | 9 | — | Sep 17, 2026 | Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPDATE access... |
| CVE-2026-54053 | CRITICAL | 9.6 | 1.1% | Sep 17, 2026 | Many Notes is a Markdown note-taking web application designed for simplicity. Prior to 0.16.0, the ZIP vault import impl... |
| CVE-2026-92489 | CRITICAL | 9.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: xfrm: Fix skb double-free in xfrm_dev_direct_output... |
| CVE-2026-90414 | CRITICAL | 9.1 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: IB/isert: reject PDUs declaring more data than was ... |
| CVE-2026-90413 | CRITICAL | 9.1 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: IB/isert: reject login PDUs declaring more data tha... |
| CVE-2026-90235 | CRITICAL | 9.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: sunrpc: xprtsock: annotate shared socket callbacks ... |
| CVE-2026-90230 | CRITICAL | 9.1 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: nvmet: fix heap out-of-bounds read in nvmet_auth_ne... |
| CVE-2026-90173 | CRITICAL | 9.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: smb: smbdirect: free completion queues with ib_free... |
| CVE-2026-90151 | CRITICAL | 9.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: NFSv4: remove callback IDR entry on client allocati... |
| CVE-2026-90110 | CRITICAL | 9.4 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: inetpeer: randomize RB-tree node comparison using S... |
| CVE-2026-90104 | CRITICAL | 9.8 | — | Sep 17, 2026 | In the Linux kernel, the following vulnerability has been resolved: NFSv4.1: zero referring call lists before decoding ... |
| CVE-2026-91039 | CRITICAL | 9.1 | — | Sep 17, 2026 | Authentication Bypass by Spoofing vulnerability in team-alembic ash_authentication allows an attacker who operates one i... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now