2026 CVE Vulnerabilities
65,293 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-80359 | MEDIUM | 6.8 | — | Sep 28, 2026 | Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface W... |
| CVE-2026-80358 | MEDIUM | 5.1 | — | Sep 28, 2026 | Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface W... |
| CVE-2026-80357 | HIGH | 7 | — | Sep 28, 2026 | Dell Boot Optimized Server Storage (BOSS), versions prior to 2.2.13.2038, contains an On-Chip Debug and Test Interface W... |
| CVE-2026-70413 | MEDIUM | 5.6 | — | Sep 28, 2026 | Dell Live Optics Collector, versions prior to 27.2.13.310, contain(s) a Use of Hard-coded Password vulnerability. A low ... |
| CVE-2026-4556 | HIGH | 7.8 | — | Sep 28, 2026 | Exam4 is affected by a local privilege escalation vulnerability in the com.extegrity.LogTool privileged helper, which co... |
| CVE-2026-101333 | LOW | 3.7 | — | Sep 28, 2026 | A flaw was found in the Micrometer user-event metrics listener of Keycloak, a solution for integrated identity and acces... |
| CVE-2026-101075 | CRITICAL | 10 | — | Sep 28, 2026 | A security vulnerability has been detected in Netcore NR289-GE 1.4.5102. The impacted element is the function system of ... |
| CVE-2026-101074 | CRITICAL | 9.8 | — | Sep 28, 2026 | A weakness has been identified in Netcore NR289-GE 1.4.5102. The affected element is the function password-check of the ... |
| CVE-2026-101073 | HIGH | 8.3 | — | Sep 28, 2026 | A security flaw has been discovered in Netcore NR289-GE 1.4.5102. Impacted is an unknown function of the file /bin/boa o... |
| CVE-2026-97335 | HIGH | 7.7 | — | Sep 28, 2026 | Incorrect authorization in the custom storage volume creation endpoint in Canonical LXD versions 5.0.0 and later (fixed ... |
| CVE-2026-93537 | MEDIUM | 6.5 | — | Sep 28, 2026 | A user who can supply bundle content to a repository referenced by a GitRepo resource, for example through Git push acce... |
| CVE-2026-90926 | HIGH | 8.8 | — | Sep 28, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Cons... |
| CVE-2026-90925 | HIGH | 7.1 | — | Sep 28, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innotim Software, Teleco... |
| CVE-2026-90924 | CRITICAL | 9.8 | — | Sep 28, 2026 | Use of default credentials vulnerability in Innotim Software, Telecommunications and Consultancy Trade Ltd. Co. Logsign ... |
| CVE-2026-87799 | CRITICAL | 9.9 | — | Sep 28, 2026 | Improper link resolution in the migration receive path in Canonical LXD versions 4.0 and later (fixed in 4.0.14, 5.0.10,... |
| CVE-2026-87798 | MEDIUM | 5.8 | — | Sep 28, 2026 | Improper link resolution in the recursive file pull feature of the LXD CLI client in Canonical LXD versions 4.0.2 up to ... |
| CVE-2026-86595 | HIGH | 8.8 | — | Sep 28, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Iron Mountain Arch... |
| CVE-2026-86335 | MEDIUM | 6.3 | — | Sep 28, 2026 | Missing Authorization in imageDownload in Canonical LXD before 5.0.10, 5.21.8, and 6.10 on Linux allows a project-restri... |
| CVE-2026-86334 | MEDIUM | 4.2 | — | Sep 28, 2026 | Path traversal in the CLI client image export and copy functionality in Canonical LXD from 4.0.2 before 4.0.14, 5.0.10, ... |
| CVE-2026-85526 | CRITICAL | 9.9 | — | Sep 28, 2026 | Path traversal in the Btrfs storage driver (unpackVolume) in Canonical LXD on Linux allows an authenticated user with in... |
| CVE-2026-85185 | CRITICAL | 9.6 | — | Sep 28, 2026 | Path traversal in the btrfs storage driver in Canonical LXD versions 4.0.2 and later (fixed in 4.0.14, 5.0.10, 5.21.8 an... |
| CVE-2026-73642 | CRITICAL | 9.2 | — | Sep 28, 2026 | Dayforce Payroll is vulnerable to Path Traversal in file download functionality. An unauthenticated attacker can sent G... |
| CVE-2026-73641 | MEDIUM | 5.1 | — | Sep 28, 2026 | Dayforce Payroll is vulnerable to Reflected XSS in multiple endpoints. An attacker can prepare a specially crafted URL t... |
| CVE-2026-73640 | CRITICAL | 9.3 | — | Sep 28, 2026 | Dayforce Payroll is vulnerable to Time Based-Blind SQL Injection in password recovery functionality. The unauthenticated... |
| CVE-2026-15953 | MEDIUM | 5 | — | Sep 28, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Protection and contr... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now