2026 CVE Vulnerabilities
64,751 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-82164 | HIGH | 7.1 | 0.1% | Sep 24, 2026 | Dell Trusted Device Client, versions prior to 8.1.359.0, contain an Incorrect Permission Assignment for Critical Resourc... |
| CVE-2026-77967 | HIGH | 8.1 | 0.2% | Sep 24, 2026 | The Botslab G980H dash camera firmware accepts a reusable authentication value without adequately verifying its freshnes... |
| CVE-2026-96749 | HIGH | 8.4 | 0.1% | Sep 24, 2026 | An integer overflow in the BSON document encoding component of the MongoDB Python Driver's bundled native extension may ... |
| CVE-2026-89325 | HIGH | 7.8 | 0.1% | Sep 24, 2026 | An uncontrolled search path element in InsightVM assessment content in Rapid7 Insight Agent on Windows allows a local, l... |
| CVE-2026-86859 | HIGH | 8.7 | — | Sep 24, 2026 | ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This... |
| CVE-2026-86858 | HIGH | 8.7 | — | Sep 24, 2026 | ServiceNow has remediated an improper access control security issue that was identified in the ServiceNow AI Platform. T... |
| CVE-2026-86857 | HIGH | 8.4 | — | Sep 24, 2026 | ServiceNow has remediated an authorization bypass security issue that was identified in the ServiceNow AI Platform. This... |
| CVE-2026-82371 | HIGH | 8.5 | — | Sep 24, 2026 | Plaintext exposure of sensitive authentication data in Brocade SANnav discovery service log files enables individuals wi... |
| CVE-2026-82157 | HIGH | 8.3 | — | Sep 24, 2026 | Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contains an Improper Certificate Validation vulnerabil... |
| CVE-2026-81473 | HIGH | 8.1 | 0.1% | Sep 24, 2026 | Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low priv... |
| CVE-2026-81455 | HIGH | 8.6 | — | Sep 24, 2026 | Dell ThinOS 10, versions prior to SecurityAddon_2605.10.2766_T10, contain a Missing Authentication for Critical Function... |
| CVE-2026-77294 | HIGH | 8.1 | — | Sep 24, 2026 | TREK is a collaborative travel planner. Prior to 3.3.0, TREK allows an authenticated user to store an attacker-controlle... |
| CVE-2026-77293 | HIGH | 7.1 | — | Sep 24, 2026 | TREK is a collaborative travel planner. Prior to 3.3.0, the DELETE /api/trips/:tripId/collab/notes/:noteId/files/:fileId... |
| CVE-2026-61825 | HIGH | 8.7 | — | Sep 24, 2026 | code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before... |
| CVE-2026-61823 | HIGH | 7.3 | — | Sep 24, 2026 | code16 Sharp is a Laravel-based framework for building content-management and administrative interfaces. Versions before... |
| CVE-2026-57440 | HIGH | 7.5 | — | Sep 24, 2026 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for em... |
| CVE-2026-48070 | HIGH | 7.1 | — | Sep 24, 2026 | Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.1, authenticated users can store att... |
| CVE-2026-13248 | HIGH | 8.8 | — | Sep 24, 2026 | An Authenticated Remote Code Execution via Arbitrary File Write in the Intermec Fingerprint Command Interface vulnerabil... |
| CVE-2026-95985 | HIGH | 8.8 | — | Sep 24, 2026 | The file write tool in Amazon Kiro IDE versions before 1.0.242 might allow remote unauthenticated actors to inject craft... |
| CVE-2026-85057 | HIGH | 8.7 | — | Sep 24, 2026 | ZITADEL is an open source identity management platform. From 3.0.0 until 3.4.13 and 4.16.1, ZITADEL Actions V1 enables t... |
| CVE-2026-85056 | HIGH | 8.2 | — | Sep 24, 2026 | ZITADEL is an open source identity management platform. From 4.0.0 until 4.16.1, ZITADEL Login V2 creates a browser sess... |
| CVE-2026-71540 | HIGH | 7.5 | — | Sep 24, 2026 | Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. F... |
| CVE-2026-63645 | HIGH | 7.5 | — | Sep 24, 2026 | OpenObserve is a cloud-native observability platform. Prior to 0.90.3, OpenObserve registers the /config/runtime endpoin... |
| CVE-2026-61816 | HIGH | 7.5 | — | Sep 24, 2026 | zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading mess... |
| CVE-2026-61815 | HIGH | 7.2 | — | Sep 24, 2026 | zbateson/mail-mime-parser is a mail mime parser alternative to PHP's imap* functions and Pear libraries for reading mess... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now