2026 CVE Vulnerabilities
67,127 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-97059 | HIGH | 8.2 | 0.3% | Sep 24, 2026 | DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without... |
| CVE-2026-97058 | MEDIUM | 5.3 | — | Sep 24, 2026 | sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods withou... |
| CVE-2026-97057 | HIGH | 7.5 | — | Sep 24, 2026 | redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to... |
| CVE-2026-95521 | HIGH | 7.8 | — | Sep 24, 2026 | A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames con... |
| CVE-2026-95519 | HIGH | 7.8 | — | Sep 24, 2026 | A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation usi... |
| CVE-2026-91187 | CRITICAL | 9.3 | — | Sep 24, 2026 | Improper Verification of Cryptographic Signature vulnerability in dashbit nimble_zta allows an unauthenticated remote at... |
| CVE-2026-88360 | — | — | — | Sep 24, 2026 | libvips 8.19.0 contains a memory access vulnerability when processing little-endian PFM images. If the PFM text header l... |
| CVE-2026-88359 | MEDIUM | 6.5 | 0.2% | Sep 24, 2026 | libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_iter_format(). When processing a specially crafted Y... |
| CVE-2026-77798 | MEDIUM | 6.5 | — | Sep 24, 2026 | Velociraptor contains a deadlock condition that may be triggered by authenticated users. The issue stems from a lock man... |
| CVE-2026-77797 | LOW | 3.6 | — | Sep 24, 2026 | Velociraptor's prefetch library contains an out of bound vulnerability which may cause a crash when parsing certain malf... |
| CVE-2026-18857 | LOW | 3.4 | 0.1% | Sep 24, 2026 | IBM OPENBMC FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, and FW1060.00 through FW1060.81 is affected by a v... |
| CVE-2026-18104 | LOW | 3.3 | — | Sep 24, 2026 | IBM Db2 Mirror for i 7.6, 7.5, and 7.4 could allow a local attacker to obtain sensitive information due to the use of th... |
| CVE-2026-17511 | LOW | 3.4 | 0.1% | Sep 24, 2026 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.... |
| CVE-2026-17504 | MEDIUM | 4.4 | 0.1% | Sep 24, 2026 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.... |
| CVE-2026-17503 | MEDIUM | 5.1 | 0.1% | Sep 24, 2026 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.... |
| CVE-2026-17413 | MEDIUM | 5.1 | 0.1% | Sep 24, 2026 | IBM PowerVM Hypervisor FW1120.00 through FW1120.01, FW1110.00 through FW1110.31, FW1060.00 through FW1060.81, and FW950.... |
| CVE-2026-97182 | HIGH | 7.3 | — | Sep 24, 2026 | A security vulnerability has been detected in halo-dev Halo up to 2.25.4/2.26.1. Affected is an unknown function of the ... |
| CVE-2026-96515 | HIGH | 8.6 | — | Sep 24, 2026 | This vulnerability exists in the Netlink ICT HG323RW router due to insufficient authorization and input validation contr... |
| CVE-2026-94416 | MEDIUM | 6.8 | — | Sep 24, 2026 | An authorization bypass was found in the Ansible Automation Platform (AAP) gateway. The gateway API allows an authentica... |
| CVE-2026-88916 | MEDIUM | 6.8 | — | Sep 24, 2026 | Incorrect Authorization vulnerability in TÜBİTAK ULAKBİM UlakPDF allows Privilege Escalation. This issue affects UlakPD... |
| CVE-2026-88907 | HIGH | 7.4 | — | Sep 24, 2026 | Incorrect Authorization vulnerability in TÜBİTAK ULAKBİM UlakPDF allows Authentication Bypass. This issue affects UlakP... |
| CVE-2026-19072 | CRITICAL | 9.9 | — | Sep 24, 2026 | Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each e... |
| CVE-2026-97311 | MEDIUM | 4.3 | — | Sep 24, 2026 | A flaw was found in the Admin REST API of Keycloak, an identity and access management solution. The endpoints used to re... |
| CVE-2026-7169 | HIGH | 7.5 | — | Sep 24, 2026 | a vulnerability involving an unchecked search path element in Evope Collector, versions prior to 1.1.7.13, allows a loca... |
| CVE-2026-4806 | MEDIUM | 6.5 | — | Sep 24, 2026 | The Custom Thank You Page for WooCommerce plugin for WordPress is vulnerable to unauthorized access and loss of data due... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now