2026 CVE Vulnerabilities
64,755 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-91132 | MEDIUM | 4.3 | — | Sep 24, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.8, 2026.6.3, 2026.7.2, and 2026.8.0, sites using wildca... |
| CVE-2026-88384 | MEDIUM | 5.5 | — | Sep 24, 2026 | OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribute parsing path. A specially crafted EXR file conta... |
| CVE-2026-88367 | MEDIUM | 6.5 | 0.1% | Sep 24, 2026 | NanoSVG 239e102ec contains an incorrect numeric conversion vulnerability in nsvg__curveDivs() during SVG stroke rasteriz... |
| CVE-2026-84302 | MEDIUM | 4.2 | — | Sep 24, 2026 | Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Discourse AI revie... |
| CVE-2026-79763 | MEDIUM | 5.3 | — | Sep 24, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.4.0... |
| CVE-2026-79762 | MEDIUM | 5.5 | — | Sep 24, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0... |
| CVE-2026-47132 | MEDIUM | 5.4 | — | Sep 24, 2026 | phpMyFAQ is an open source FAQ web application. Prior to version 4.2.0-alpha, an authenticated SQL LIKE wildcard injecti... |
| CVE-2026-26054 | MEDIUM | 6.8 | — | Sep 24, 2026 | SumatraPDF is a multi-format reader for Windows. Prior to 3.6, the MobiDoc::ParseHeader function in src/MobiDoc.cpp vali... |
| CVE-2026-97226 | MEDIUM | 6.3 | — | Sep 24, 2026 | A vulnerability has been found in DbGate up to 7.2.5/7.3.1-premium-beta.1. This impacts the function fs.readFile of the ... |
| CVE-2026-97225 | MEDIUM | 6.3 | 0.2% | Sep 24, 2026 | A flaw has been found in DbGate up to 7.2.5-beta.5. This affects an unknown function of the file packages/api/src/contro... |
| CVE-2026-96873 | MEDIUM | 5.5 | — | Sep 24, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cirrus... |
| CVE-2026-96746 | MEDIUM | 6.5 | — | Sep 24, 2026 | An out-of-bounds write in the connection-monitoring logic of the MongoDB C Driver may allow an unauthenticated party who... |
| CVE-2026-96745 | MEDIUM | 5.6 | — | Sep 24, 2026 | Deserialization of untrusted data in the command monitoring support of the MongoDB PHP Driver can cause class names embe... |
| CVE-2026-93541 | MEDIUM | 6.5 | — | Sep 24, 2026 | An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1.8.4 could be used by a |
| CVE-2026-92680 | MEDIUM | 5.5 | 0.2% | Sep 24, 2026 | Araxis Merge for Windows version 2011.4074 through 2026.0 stores user-configured credentials for remote servers in the W... |
| CVE-2026-88370 | MEDIUM | 5.3 | 0.1% | Sep 24, 2026 | libconfini 1.16.4 contains a heap out-of-bounds write condition involving the bundled load_ini_buffer.h utility and stri... |
| CVE-2026-79761 | MEDIUM | 6.6 | — | Sep 24, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0... |
| CVE-2026-79760 | MEDIUM | 6.4 | — | Sep 24, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 2.5.0... |
| CVE-2026-79759 | MEDIUM | 4.3 | — | Sep 24, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.7.0... |
| CVE-2026-79758 | MEDIUM | 5.4 | — | Sep 24, 2026 | Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. From 1.8.0... |
| CVE-2026-76907 | MEDIUM | 6.5 | — | Sep 24, 2026 | LaSuite Doc is a collaborative note taking, wiki and documentation platform. From 4.8.2 until 5.4.0, GET /api/v1.0/docum... |
| CVE-2026-67233 | MEDIUM | 6 | — | Sep 24, 2026 | RabbitMQ is a messaging and streaming broker. Prior to versions 3.13.15, 4.0.20, 4.1.11, 4.2.6, and 4.3.1, The shovel ma... |
| CVE-2026-97224 | MEDIUM | 4.3 | — | Sep 24, 2026 | A vulnerability was detected in Excalidraw up to 0.18.1. The impacted element is an unknown function of the file package... |
| CVE-2026-77825 | MEDIUM | 4.9 | 0.3% | Sep 24, 2026 | IBM ContextForge MCP Gateway 1.0.0 through 1.0.8 was vulnerable to path traversal in its Admin API log-download endpoint... |
| CVE-2026-77707 | MEDIUM | 5.9 | — | Sep 24, 2026 | Improper certificate validation vulnerability in HAVELSAN Inc. Liman Render Engine allows Adversary in the Middle (AiTM)... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now