2026 CVE Vulnerabilities
67,213 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93349 | HIGH | 8.8 | — | Sep 23, 2026 | Frictionless before 5.19.1 contains an OS command injection vulnerability in the explore console command that allows an ... |
| CVE-2026-88832 | HIGH | 7.3 | 0.1% | Sep 23, 2026 | BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow wh... |
| CVE-2026-88830 | HIGH | 7.5 | — | Sep 23, 2026 | A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow ... |
| CVE-2026-85724 | CRITICAL | 9.6 | 0.3% | Sep 23, 2026 | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, when pattern-based ACL rules are configured, Authorizations... |
| CVE-2026-6669 | MEDIUM | 5.9 | — | Sep 23, 2026 | Missing upper bound on the key derivation iteration count accepted during SCRAM authentication to a backend server in Pg... |
| CVE-2026-6668 | HIGH | 7.5 | — | Sep 23, 2026 | Integer overflow in the packet buffer growth logic in PgBouncer through 1.25.2 allows an unauthenticated remote attacker... |
| CVE-2026-19888 | HIGH | 7.5 | — | Sep 23, 2026 | Missing validation of a mandatory attribute in the SCRAM client-final-message parser in PgBouncer through 1.25.2 allows ... |
| CVE-2026-96675 | LOW | 3.3 | 0.1% | Sep 23, 2026 | alsa-lib through 1.2.16.1 contains a denial of service vulnerability in the multi PCM plugin that fails to validate spar... |
| CVE-2026-96674 | MEDIUM | 4.4 | 0.1% | Sep 23, 2026 | alsa-lib through 1.2.16.1 computes combined topology element size using 32-bit arithmetic in src/topology/ctl.c, allowin... |
| CVE-2026-96673 | HIGH | 7.5 | 0.4% | Sep 23, 2026 | Photoview through 2.4.0 contains an SQL injection vulnerability in the album download route that allows unauthenticated ... |
| CVE-2026-96672 | MEDIUM | 6.4 | — | Sep 23, 2026 | Frappe ERPNext versions before 16.34.1 fail to validate that Financial Report Template calculation_formula values refere... |
| CVE-2026-93769 | HIGH | 7.2 | — | Sep 23, 2026 | HumHub 1.18.5 is affected by a stored cross-site scripting (XSS) vulnerability that allows any user holding the delegate... |
| CVE-2026-79310 | HIGH | 8.5 | 0.7% | Sep 23, 2026 | webpy web.py 0.76 is vulnerable to server-side template injection (SSTI). The template engine can be tricked into execut... |
| CVE-2026-79306 | MEDIUM | 6.5 | 0.3% | Sep 23, 2026 | CyberPanel v1.9.1 contains a path traversal vulnerability in the compress method exposed through the /filemanager/contro... |
| CVE-2026-79304 | MEDIUM | 6.5 | 0.4% | Sep 23, 2026 | CyberPanel 1.9.1 contains a path traversal vulnerability in the readFileContents method of the /filemanager/controller e... |
| CVE-2026-6327 | MEDIUM | 4.3 | — | Sep 23, 2026 | IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to inject data into log messages due to improper neutra... |
| CVE-2026-4921 | LOW | 2.7 | — | Sep 23, 2026 | IBM Guardium Data Protection 12.2 could allow an administrative user to obtain sensitive information when a detailed tec... |
| CVE-2026-3626 | MEDIUM | 5.3 | — | Sep 23, 2026 | IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to obtain sensitive information when a detailed technical ... |
| CVE-2026-19267 | MEDIUM | 6.2 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to missing authentication on the Business Rul... |
| CVE-2026-19179 | HIGH | 8.2 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to manipulate database querie... |
| CVE-2026-19087 | MEDIUM | 4.4 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a local attacker to achieve privilege escalatio... |
| CVE-2026-18875 | HIGH | 7.3 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to RAG poisoning via unauthenticated runbook ... |
| CVE-2026-18872 | CRITICAL | 9.3 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to stored cross-site scripting (CWE-79) in th... |
| CVE-2026-18505 | MEDIUM | 5.4 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to open redirect in the PMP `HostHeaderFilter... |
| CVE-2026-18490 | HIGH | 8.8 | — | Sep 23, 2026 | IBM Financial Transaction Manager (FTM) for RedHat OpenShift is vulnerable to unauthenticated remote code execution via ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now