2026 CVE Vulnerabilities
64,997 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-57166 | MEDIUM | 5.3 | 0.4% | Sep 4, 2026 | PJSIP is a free and open source multimedia communication library written in C. Prior to commit 4472a31, a stack buffer o... |
| CVE-2026-57165 | MEDIUM | 5.3 | 0.4% | Sep 4, 2026 | PJSIP is a free and open source multimedia communication library written in C. Prior to commit 628b716, a stack buffer o... |
| CVE-2026-57164 | MEDIUM | 5.9 | 0.3% | Sep 4, 2026 | PJSIP is a free and open source multimedia communication library written in C. Prior to commit 8d5956a, a heap buffer ov... |
| CVE-2026-57160 | MEDIUM | 5.3 | 0.4% | Sep 4, 2026 | PJSIP is a free and open source multimedia communication library written in C. Prior to commit d6a0e7f, a buffer overflo... |
| CVE-2026-53760 | MEDIUM | 5.2 | 0.1% | Sep 4, 2026 | Admidio is an open-source user management solution. In versions 5.0.11 and prior, the modules/plugins.php endpoint handl... |
| CVE-2026-53757 | MEDIUM | 6.9 | 0.3% | Sep 4, 2026 | Emlog is an open source website building system. In versions 2.6.29 and prior, the emUnZip() function extracts all ZIP e... |
| CVE-2026-53756 | MEDIUM | 4.9 | 0.3% | Sep 4, 2026 | Emlog is an open source website building system. Prior to version 2.6.16, Emlog CMS Pro contains a blind SQL injection i... |
| CVE-2026-18149 | MEDIUM | 5.9 | 0.3% | Sep 4, 2026 | undici's retry handler can leave an already-exposed response body pending forever. When a server returns a successful re... |
| CVE-2026-85024 | MEDIUM | 5.9 | 0.3% | Sep 4, 2026 | undici bundles a WebSocket client whose permessage-deflate size-limit cleanup removes all listeners from the internal zl... |
| CVE-2026-85008 | MEDIUM | 5.3 | 0.1% | Sep 4, 2026 | undici's cache interceptor documents that only safe HTTP methods are cached, but its logic to skip caching is built by s... |
| CVE-2026-84947 | MEDIUM | 5.3 | 0.2% | Sep 4, 2026 | undici's dump interceptor reads and discards a response body up to a configurable maximum size. When a response declares... |
| CVE-2026-78849 | MEDIUM | 5.4 | 0.3% | Sep 4, 2026 | Cross Site Scripting vulnerability in Netgate pfSense Plus software versions <= 26.03 pfSense CE software versions <= 2.... |
| CVE-2026-38961 | MEDIUM | 5.4 | 0.2% | Sep 4, 2026 | Cross-Site Scripting (XSS) vulnerability in the RSS Widget of Netgate pfSense Plus (versions 26.03, 25.11.1) and pfSense... |
| CVE-2026-18078 | MEDIUM | 6.5 | 0.3% | Sep 4, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to an integer ... |
| CVE-2026-18076 | MEDIUM | 6.5 | 0.3% | Sep 4, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a memory le... |
| CVE-2026-18073 | MEDIUM | 4.4 | 0.1% | Sep 4, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to inject parameters into a CL command due to im... |
| CVE-2026-17631 | MEDIUM | 6.5 | 0.2% | Sep 4, 2026 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to... |
| CVE-2026-17622 | MEDIUM | 6.5 | 0.5% | Sep 4, 2026 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to... |
| CVE-2026-17621 | MEDIUM | 5.4 | 0.3% | Sep 4, 2026 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker c... |
| CVE-2026-17469 | MEDIUM | 5.5 | 0.3% | Sep 4, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to cause a denial of service due to an off-by-on... |
| CVE-2026-17444 | MEDIUM | 6.5 | 0.3% | Sep 4, 2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 1... |
| CVE-2026-17443 | MEDIUM | 6.5 | 0.3% | Sep 4, 2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 1... |
| CVE-2026-17442 | MEDIUM | 5.5 | 0.1% | Sep 4, 2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 1... |
| CVE-2026-17440 | MEDIUM | 5.5 | 0.1% | Sep 4, 2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 1... |
| CVE-2026-17274 | MEDIUM | 5.4 | 0.2% | Sep 4, 2026 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to predicta... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now