2026 CVE Vulnerabilities
67,127 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-77703 | MEDIUM | 5.9 | — | Sep 24, 2026 | Key exchange without entity authentication vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Mi... |
| CVE-2026-73064 | LOW | 2.9 | — | Sep 24, 2026 | In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker who can cause an entropy source to fail can remove o... |
| CVE-2026-6544 | MEDIUM | 6.2 | — | Sep 24, 2026 | IBM Concert 1.0.0 through 3.0.0 allows recursive copying of directories without proper controls which can lead to uninte... |
| CVE-2026-65422 | MEDIUM | 6.5 | — | Sep 24, 2026 | A flaw in the authorization mechanism for Media Gateway API in Genetec Security Center may allow a user with no playback... |
| CVE-2026-58008 | HIGH | 8.1 | — | Sep 24, 2026 | Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured... |
| CVE-2026-58007 | HIGH | 8.1 | — | Sep 24, 2026 | Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configur... |
| CVE-2026-58006 | HIGH | 8.1 | — | Sep 24, 2026 | Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configur... |
| CVE-2026-58005 | HIGH | 8.1 | — | Sep 24, 2026 | Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS allows Privilege Escalation and Overflow Buffers. Th... |
| CVE-2026-58004 | HIGH | 8.1 | — | Sep 24, 2026 | Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS allows Privilege Escalation and Overflow Buffers. Th... |
| CVE-2026-56736 | HIGH | 8.2 | — | Sep 24, 2026 | phpMyFAQ is an open source FAQ web application. A stored cross-site scripting (XSS) vulnerability in versions prior to 4... |
| CVE-2026-52001 | — | — | — | Sep 24, 2026 | An issue in geelen mcp-remote 0.1.18 through 0.1.38 allows a remote attacker to obtain sensitive information via the SSE... |
| CVE-2026-51997 | HIGH | 8.8 | 0.3% | Sep 24, 2026 | An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the open() fu... |
| CVE-2026-51996 | CRITICAL | 9.8 | 0.8% | Sep 24, 2026 | An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the src/lib/u... |
| CVE-2026-51995 | HIGH | 7.5 | — | Sep 24, 2026 | An issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote attacker to obtain sensitive information via the src... |
| CVE-2026-51994 | CRITICAL | 9.1 | 0.2% | Sep 24, 2026 | mcp-remote versions 0.1.32 through 0.1.38 are vulnerable to Server-Side Request Forgery (SSRF) via the resource_metadata... |
| CVE-2026-19492 | LOW | 3.2 | 0.1% | Sep 24, 2026 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affe... |
| CVE-2026-18870 | MEDIUM | 4.3 | 0.2% | Sep 24, 2026 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.... |
| CVE-2026-13467 | HIGH | 8.1 | — | Sep 24, 2026 | Out-of-bounds write vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Impl... |
| CVE-2026-13466 | HIGH | 8.1 | — | Sep 24, 2026 | Incorrect calculation of buffer size vulnerability in Altera Trusted Firmware on HPS allows Overflow Buffers. This issu... |
| CVE-2026-13465 | HIGH | 8.1 | — | Sep 24, 2026 | Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured... |
| CVE-2026-12559 | HIGH | 7.3 | — | Sep 24, 2026 | A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solu... |
| CVE-2026-97360 | CRITICAL | 10 | — | Sep 24, 2026 | HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticat... |
| CVE-2026-97359 | CRITICAL | 10 | — | Sep 24, 2026 | HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows u... |
| CVE-2026-97062 | MEDIUM | 5.4 | 0.2% | Sep 24, 2026 | Aureus ERP through 1.6.0, fixed in commit 53ad76d, stores uploaded SVG files on its public disk and serves them from the... |
| CVE-2026-97061 | MEDIUM | 4.3 | — | Sep 24, 2026 | Black Candy through 3.2.1 fails to scope playlist search queries to the authenticated session user, allowing any authent... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now