2026 CVE Vulnerabilities
67,111 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-62368 | HIGH | 8.4 | 0.3% | Sep 24, 2026 | Snipe-IT is an IT asset/license management system. Prior to 8.7.0, a user with the customfields.create permission can st... |
| CVE-2026-56744 | HIGH | 8.7 | 0.3% | Sep 24, 2026 | `@bsv/wallet-toolbox` provides BRC-100 wallet signing and storage components, while `@bsv/wallet-toolbox-client` and `@b... |
| CVE-2026-56738 | HIGH | 8.5 | — | Sep 24, 2026 | phpMyFAQ is an open source FAQ web application. The `StopWords::add()` method inversions prior to 4.1.6 builds a SQL `IN... |
| CVE-2026-47132 | MEDIUM | 5.4 | — | Sep 24, 2026 | phpMyFAQ is an open source FAQ web application. Prior to version 4.2.0-alpha, an authenticated SQL LIKE wildcard injecti... |
| CVE-2026-26054 | MEDIUM | 6.8 | — | Sep 24, 2026 | SumatraPDF is a multi-format reader for Windows. Prior to 3.6, the MobiDoc::ParseHeader function in src/MobiDoc.cpp vali... |
| CVE-2026-97226 | MEDIUM | 6.3 | — | Sep 24, 2026 | A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1. This impacts the function fs.readFile of the ... |
| CVE-2026-97225 | MEDIUM | 6.3 | 0.2% | Sep 24, 2026 | A flaw has been found in DbGate up to 7.2.5-beta.5. This affects an unknown function of the file packages/api/src/contro... |
| CVE-2026-96873 | MEDIUM | 5.5 | — | Sep 24, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cirrus... |
| CVE-2026-96750 | HIGH | 7.1 | — | Sep 24, 2026 | MongoDB Compass can interpolate a database name without escaping into the initial input of its embedded MongoDB shell wh... |
| CVE-2026-96746 | MEDIUM | 6.5 | — | Sep 24, 2026 | An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who... |
| CVE-2026-96745 | MEDIUM | 5.6 | — | Sep 24, 2026 | Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embe... |
| CVE-2026-96744 | HIGH | 7.1 | — | Sep 24, 2026 | Improper neutralization of special elements in data query logic in the cache lock implementation of the MongoDB integrat... |
| CVE-2026-93541 | MEDIUM | 6.5 | — | Sep 24, 2026 | An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a |
| CVE-2026-93425 | CRITICAL | 9.9 | — | Sep 24, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the patch.readRepoDirectories tRPC proc... |
| CVE-2026-93283 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: i3c: master: Fix device_register() error path When... |
| CVE-2026-93282 | HIGH | 8.1 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix maximum allowed access checks The DACL ... |
| CVE-2026-93281 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: wifi: rtw89: fix HE extended capability length chec... |
| CVE-2026-93280 | HIGH | 8.8 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: greybus: audio: bound the topology section sizes ag... |
| CVE-2026-93279 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: staging: octeon: add missing tasklet_kill in cvm_oc... |
| CVE-2026-93278 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: staging: octeon: add missing napi_disable in cvm_oc... |
| CVE-2026-93277 | HIGH | 7.8 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Validate udata before executing comma... |
| CVE-2026-93276 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: phy: renesas: phy-rcar-gen3-usb2: Fix devm action r... |
| CVE-2026-93275 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: perf/x86/intel/pt: Fix stop/start with no update I... |
| CVE-2026-93274 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: pinctrl: bcm2835: Don't remove an unregistered GPIO... |
| CVE-2026-93273 | — | — | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: regulator: tps6594: Fix device node reference leaks... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now