2026 CVE Vulnerabilities
67,211 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-71461 | MEDIUM | 4.3 | 0.2% | Sep 23, 2026 | HostList.list() catches bare Exception and returns str(e) verbatim. Via host_filter, any authenticated use... |
| CVE-2026-71460 | MEDIUM | 4.3 | — | Sep 23, 2026 | /api/v2/config/ is protected only by IsAuthenticated. license_info (account_number, subscription_id, pool_... |
| CVE-2026-71459 | MEDIUM | 5 | 0.3% | Sep 23, 2026 | JobJobEventsChildrenSummary view has no model/parent_model. ModelAccessPermission.check_get_permissions() ... |
| CVE-2026-71458 | MEDIUM | 5 | — | Sep 23, 2026 | URLModificationMiddleware resolves named-URL lookups against unfiltered Model.objects before RBAC. The 403... |
| CVE-2026-63132 | CRITICAL | 9.2 | 0.5% | Sep 23, 2026 | OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's handleLogicalRecovery path... |
| CVE-2026-63131 | MEDIUM | 6 | 0.4% | Sep 23, 2026 | OpenBao is an open source identity-based secrets management system. Prior to 2.6.0, OpenBao's vault/policy/acl.go could ... |
| CVE-2026-61814 | HIGH | 7.5 | 0.6% | Sep 23, 2026 | Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser can perform quadratic work when a single JSON tok... |
| CVE-2026-61695 | HIGH | 7.5 | 0.6% | Sep 23, 2026 | Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.1 and 7.0.0-alpha04, Wire's S... |
| CVE-2026-59990 | HIGH | 7.5 | 0.6% | Sep 23, 2026 | Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods accept arbitrarily deep JSON array and object nes... |
| CVE-2026-55632 | MEDIUM | 4.3 | 0.3% | Sep 23, 2026 | GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal pipeline structure API used for autocompleti... |
| CVE-2026-55456 | — | — | — | Sep 23, 2026 | Rejected reason: This CVE is a duplicate of another CVE. |
| CVE-2026-52744 | MEDIUM | 5.3 | 0.4% | Sep 23, 2026 | GoCD is a continuous deliver server. From 20.2.0 until 26.1.0, the internal GoCD UI fetch-artifact auto-suggestion API a... |
| CVE-2026-91775 | HIGH | 7.4 | 0.4% | Sep 23, 2026 | LimeSurvey Community Edition 7.0.14 fails to safely encode attacker-controlled content from a crafted .lss survey file w... |
| CVE-2026-88840 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | BusyBox TLS get_client_hello() reads past the end of the input buffer when parsing a truncated ClientHello message. |
| CVE-2026-88839 | MEDIUM | 6.7 | 0.1% | Sep 23, 2026 | BusyBox passwd/group tokenize() references a stale endpoint pointer after trimming, causing an out-of-bounds write of he... |
| CVE-2026-88837 | MEDIUM | 6.5 | 0.2% | Sep 23, 2026 | BusyBox httpd treats yescrypt ($y$) password hashes as plaintext during Basic Authentication, inverting the authenticati... |
| CVE-2026-88835 | MEDIUM | 6.1 | 0.1% | Sep 23, 2026 | BusyBox dpkg read_package_field() steps past a NUL terminator on malformed .deb packages, causing an out-of-bounds heap ... |
| CVE-2026-88831 | MEDIUM | 5.3 | 0.2% | Sep 23, 2026 | BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open, leaving a parsed IP with a zeroed mask so the ru... |
| CVE-2026-86938 | HIGH | 7.3 | 0.1% | Sep 23, 2026 | A DLL hijacking vulnerability in the FileMaker Pro installer for Windows allowed a local user to execute arbitrary code ... |
| CVE-2026-86934 | CRITICAL | 9.1 | 0.1% | Sep 23, 2026 | An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an exten... |
| CVE-2026-86930 | CRITICAL | 9.1 | 0.1% | Sep 23, 2026 | An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted imag... |
| CVE-2026-86926 | HIGH | 7.8 | 0.2% | Sep 23, 2026 | A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously... |
| CVE-2026-86867 | MEDIUM | 6.5 | 0.1% | Sep 23, 2026 | Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-user chat interface contains multiple vulnerabiliti... |
| CVE-2026-18944 | — | — | — | Sep 23, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-18944. Reason: This candidate is a ... |
| CVE-2026-96808 | HIGH | 7.4 | 0.1% | Sep 23, 2026 | In Flatpak before 1.18.1, the revokefs writer, used by the flatpak-system-helper to receive repository data from unprivi... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now