2026 CVE Vulnerabilities
67,213 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18944 | — | — | — | Sep 23, 2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-18944. Reason: This candidate is a ... |
| CVE-2026-96808 | HIGH | 7.4 | 0.1% | Sep 23, 2026 | In Flatpak before 1.18.1, the revokefs writer, used by the flatpak-system-helper to receive repository data from unprivi... |
| CVE-2026-96807 | MEDIUM | 4 | 0.1% | Sep 23, 2026 | In Flatpak before 1.18.1, a malicious sandboxed app can replace ~/.var/app/$appid/.ld.so with a symlink, causing regener... |
| CVE-2026-96804 | HIGH | 8.8 | — | Sep 23, 2026 | MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security contr... |
| CVE-2026-96775 | HIGH | 8.8 | — | Sep 23, 2026 | MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when... |
| CVE-2026-96759 | CRITICAL | 9.8 | — | Sep 23, 2026 | orval before 8.29.0 fails to escape the operationId parameter when emitting it into generated TanStack Query mutator opt... |
| CVE-2026-96758 | CRITICAL | 9.8 | — | Sep 23, 2026 | orval @orval/core before 8.28.0 contains a code injection vulnerability in the form-data serializer that fails to escape... |
| CVE-2026-96757 | CRITICAL | 9.8 | — | Sep 23, 2026 | orval before 8.29.0 fails to escape OpenAPI media-type keys when emitting them into single-quoted Content-Type string li... |
| CVE-2026-96756 | HIGH | 8.1 | — | Sep 23, 2026 | orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory generator that fails to e... |
| CVE-2026-96755 | CRITICAL | 9.8 | — | Sep 23, 2026 | orval versions 8.14.0 through 8.28.1 contain a code injection vulnerability in the @orval/effect generator that converts... |
| CVE-2026-96754 | CRITICAL | 9.8 | — | Sep 23, 2026 | orval versions before 8.29.0 contain a code injection vulnerability in the @orval/hono generator that fails to escape Op... |
| CVE-2026-96656 | HIGH | 7.2 | 0.3% | Sep 23, 2026 | Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary files that may be executed on load. The pr... |
| CVE-2026-96655 | MEDIUM | 4.3 | 0.2% | Sep 23, 2026 | Plex Media Server before 1.43.3.10861 allows an authenticated user to request arbitrary internal or external addresses v... |
| CVE-2026-96654 | MEDIUM | 6.5 | 0.2% | Sep 23, 2026 | Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an atta... |
| CVE-2026-96652 | MEDIUM | 4.3 | 0.2% | Sep 23, 2026 | Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can i... |
| CVE-2026-96651 | MEDIUM | 6.5 | 0.4% | Sep 23, 2026 | Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, a... |
| CVE-2026-96514 | HIGH | 7.3 | — | Sep 23, 2026 | A weakness has been identified in Neethuharii CafeManagement. Impacted is an unknown function of the file CafePortalLogi... |
| CVE-2026-96513 | HIGH | 7.3 | — | Sep 23, 2026 | A security flaw has been discovered in Neethuharii CafeManagement. This issue affects some unknown processing of the fil... |
| CVE-2026-95848 | CRITICAL | 9.1 | — | Sep 23, 2026 | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when a configured authenticator or authorizator class canno... |
| CVE-2026-95847 | HIGH | 7.5 | — | Sep 23, 2026 | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, H2PersistentQueue derives a session's message-map name as q... |
| CVE-2026-95846 | HIGH | 7.5 | 0.3% | Sep 23, 2026 | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client's Last-Will messa... |
| CVE-2026-95845 | HIGH | 7.5 | 0.3% | Sep 23, 2026 | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broker does not enforce a maximum length for pending pe... |
| CVE-2026-95844 | HIGH | 7.5 | — | Sep 23, 2026 | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, Moquette does not limit the depth of topic names and topic ... |
| CVE-2026-95843 | HIGH | 7.5 | 0.4% | Sep 23, 2026 | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.subscribe parses a shared-subscription filter th... |
| CVE-2026-95842 | HIGH | 7.5 | 0.4% | Sep 23, 2026 | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, SessionEventLoop.run catches only InterruptedException, and... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now