2026 CVE Vulnerabilities
65,007 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85381 | MEDIUM | 5.3 | 0.3% | Sep 4, 2026 | A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a061... |
| CVE-2026-49509 | MEDIUM | 4.4 | 0.1% | Sep 4, 2026 | Out-of-bounds read vulnerability in Samsung Opensource rLottie allows Overread Buffers. This issue affects rLottie: 256... |
| CVE-2026-85456 | MEDIUM | 5.5 | 0.1% | Sep 3, 2026 | MOOS-IvP through 24.8.1 fails to properly validate variable names extracted from alog files in the SplitHandler, allowin... |
| CVE-2026-85454 | MEDIUM | 6.1 | 0.2% | Sep 3, 2026 | MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a N... |
| CVE-2026-85453 | MEDIUM | 6.1 | 0.2% | Sep 3, 2026 | MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to ... |
| CVE-2026-85241 | MEDIUM | 6.3 | 0.3% | Sep 3, 2026 | A weakness has been identified in SpecterOps BloodHound up to 9.5.1. The affected element is the function NewV2API of th... |
| CVE-2026-18330 | MEDIUM | 6.1 | 0.2% | Sep 3, 2026 | A hard-coded cryptographic key vulnerability exists in the web module of TP-Link Archer AX55 v4. A LAN attacker who capt... |
| CVE-2026-9745 | MEDIUM | 6.5 | 0.2% | Sep 3, 2026 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket owners... |
| CVE-2026-9744 | MEDIUM | 5.9 | 0.1% | Sep 3, 2026 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validati... |
| CVE-2026-9736 | MEDIUM | 4.3 | 0.2% | Sep 3, 2026 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages ... |
| CVE-2026-9036 | MEDIUM | 5.9 | 0.1% | Sep 3, 2026 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validati... |
| CVE-2026-85063 | MEDIUM | 6.9 | 0.3% | Sep 3, 2026 | node-csv is a full-featured CSV parser with a simple API that is tested against large datasets. Prior to 7.0.2, csv-pars... |
| CVE-2026-85062 | MEDIUM | 6.9 | 0.3% | Sep 3, 2026 | Colord is a tiny yet powerful tool for high-performance color manipulations and conversions. Prior to 2.9.4, synchronous... |
| CVE-2026-84185 | MEDIUM | 5.9 | 0.1% | Sep 3, 2026 | A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE)... |
| CVE-2026-82521 | MEDIUM | 5.3 | 0.4% | Sep 3, 2026 | parsedmarc 9.0.6 before 11.0.1 writes forensic report sample files using an output path derived from the email subject. ... |
| CVE-2026-71429 | MEDIUM | 6.2 | 0.1% | Sep 3, 2026 | stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior... |
| CVE-2026-85044 | MEDIUM | 6.5 | 0.3% | Sep 3, 2026 | Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker lever... |
| CVE-2026-19795 | MEDIUM | 6.2 | 0.1% | Sep 3, 2026 | Qiskit could allow a local attacker to cause a denial of service due to a stack overflow during deserialization of QPY p... |
| CVE-2026-85392 | MEDIUM | 4.3 | 0.3% | Sep 3, 2026 | Peppermint through 0.5.5 contains an authorization bypass vulnerability in the GET /api/v1/auth/user/:id/logout endpoint... |
| CVE-2026-85389 | MEDIUM | 6.5 | 0.3% | Sep 3, 2026 | Worklenz before 3.0.0 fails to verify task ownership by organization when resolving task-scoped API endpoints, allowing ... |
| CVE-2026-85205 | MEDIUM | 6.3 | 0.3% | Sep 3, 2026 | A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function addw... |
| CVE-2026-82299 | MEDIUM | 6.5 | 0.2% | Sep 3, 2026 | Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Acc... |
| CVE-2026-82298 | MEDIUM | 4.3 | 0.2% | Sep 3, 2026 | Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access C... |
| CVE-2026-78596 | MEDIUM | 4.3 | 0.2% | Sep 3, 2026 | Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana... |
| CVE-2026-78595 | MEDIUM | 4.3 | 0.2% | Sep 3, 2026 | Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now