2026 CVE Vulnerabilities
67,109 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-91134 | MEDIUM | 5.4 | — | Sep 24, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the Discourse post... |
| CVE-2026-91133 | MEDIUM | 6.5 | — | Sep 24, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, authenticated user... |
| CVE-2026-91132 | MEDIUM | 4.3 | — | Sep 24, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, sites using wildca... |
| CVE-2026-91123 | HIGH | 7.2 | — | Sep 24, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the iframe src tra... |
| CVE-2026-91122 | HIGH | 8.7 | — | Sep 24, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, the video placehol... |
| CVE-2026-88390 | HIGH | 7.7 | — | Sep 24, 2026 | An out-of-bounds write vulnerability in jslGetTokenValueAsString() in Espruino 2v29 (commit bffc6d0) allows crafted Java... |
| CVE-2026-88385 | — | — | — | Sep 24, 2026 | Mini-XML 4.0.5 contains a memory leak vulnerability in mxml_load_data() during malformed XML parsing. Specially crafted ... |
| CVE-2026-88384 | MEDIUM | 5.5 | — | Sep 24, 2026 | OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribute parsing path. A specially crafted EXR file conta... |
| CVE-2026-88383 | — | — | — | Sep 24, 2026 | libical 4.0.6 contains an incompatible function pointer in icalparameter_string_to_kind(). When parsing iCalendar data c... |
| CVE-2026-88382 | HIGH | 7.5 | — | Sep 24, 2026 | hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory allocation vulnerability in its RESP aggregate pars... |
| CVE-2026-88378 | CRITICAL | 9.8 | — | Sep 24, 2026 | QuickJS commit 04be24600 contains a heap out-of-bounds write condition in JS_ReadFunctionTag(). |
| CVE-2026-88377 | MEDIUM | 6.2 | — | Sep 24, 2026 | Bento4 1.6.0.0 contains an integer underflow vulnerability in the avcC and hvcC configuration atom parsers. A specially ... |
| CVE-2026-88376 | HIGH | 7.5 | — | Sep 24, 2026 | Bento4 1.6.0.0 contains an integer underflow vulnerability in AP4_AvccAtom::Create() and AP4_HvccAtom::Create(). A speci... |
| CVE-2026-88373 | HIGH | 7.5 | 0.2% | Sep 24, 2026 | libde265 commit 4d45a6b contains a NULL pointer dereference vulnerability in the NAL parsing path. When de265_push_NAL()... |
| CVE-2026-88372 | HIGH | 7.5 | — | Sep 24, 2026 | libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_read_header() when parsing crafted MAT4 (MATLAB v4) ... |
| CVE-2026-88367 | MEDIUM | 6.5 | 0.1% | Sep 24, 2026 | NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__curveDivs() during SVG stroke rasteriz... |
| CVE-2026-84302 | MEDIUM | 4.2 | — | Sep 24, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Discourse AI revie... |
| CVE-2026-79766 | CRITICAL | 9.1 | — | Sep 24, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.1... |
| CVE-2026-79764 | HIGH | 7.7 | — | Sep 24, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.5.0... |
| CVE-2026-79763 | MEDIUM | 5.3 | — | Sep 24, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.0... |
| CVE-2026-79762 | MEDIUM | 5.5 | — | Sep 24, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0... |
| CVE-2026-63498 | MEDIUM | 5.4 | 0.2% | Sep 24, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.7.0, the uploaded-files API endpoint GET /api/v1/{object_t... |
| CVE-2026-63493 | HIGH | 8.1 | 0.3% | Sep 24, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a password-authenticated session for an account with ... |
| CVE-2026-62368 | HIGH | 8.4 | 0.3% | Sep 24, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can st... |
| CVE-2026-56744 | HIGH | 8.7 | 0.3% | Sep 24, 2026 | `@bsv/wallet-toolbox` provides BRC-100 wallet signing and storage components, while `@bsv/wallet-toolbox-client` and `@b... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now