2026 CVE Vulnerabilities
67,222 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-88344 | HIGH | 7.5 | 0.4% | Sep 22, 2026 | An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers sche... |
| CVE-2026-88341 | MEDIUM | 5.5 | 0.2% | Sep 22, 2026 | A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files. An attacker can ... |
| CVE-2026-88340 | HIGH | 7.6 | 0.2% | Sep 22, 2026 | An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vu... |
| CVE-2026-88339 | MEDIUM | 5.5 | 0.2% | Sep 22, 2026 | A NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone() function of GPAC 2d7da22e (26.08-DEV). T... |
| CVE-2026-87121 | CRITICAL | 9.8 | 0.8% | Sep 22, 2026 | lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution ... |
| CVE-2026-83805 | MEDIUM | 6.4 | 0.2% | Sep 22, 2026 | Nautobot is a Network Source of Truth and Network Automation Platform. From 3.0.0 until 3.1.8, the generic ApprovalWorkf... |
| CVE-2026-83801 | MEDIUM | 5.4 | 0.3% | Sep 22, 2026 | Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.37 and 3.1.8, a user with extras.add... |
| CVE-2026-79767 | MEDIUM | 5.5 | 0.4% | Sep 22, 2026 | Gardener implements the automated management and operation of Kubernetes clusters as a service. Prior to 1.142.6, 1.143.... |
| CVE-2026-77322 | HIGH | 7.5 | 0.6% | Sep 22, 2026 | SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3, WSConnection.Read in sip/transport_ws.go... |
| CVE-2026-76717 | MEDIUM | 5.3 | 0.4% | Sep 22, 2026 | A vulnerability exists in the Analytics and Location Engine (ALE) API that may allow for the disclosure of sensitive inf... |
| CVE-2026-76716 | MEDIUM | 5.3 | 0.5% | Sep 22, 2026 | Multiple vulnerabilities exist in the Analytics and Location Engine (ALE) that may allow for unauthorized access or deni... |
| CVE-2026-76715 | HIGH | 7.1 | 0.3% | Sep 22, 2026 | A vulnerability in an administrative component of Analytics and Location Engine (ALE) is vulnerable to a man-in-the-midd... |
| CVE-2026-76714 | HIGH | 7.2 | 0.8% | Sep 22, 2026 | Vulnerabilities in the Analytics and Location Engine web interface allows remote authenticated users to run arbitrary co... |
| CVE-2026-76713 | HIGH | 7.2 | 0.6% | Sep 22, 2026 | A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE). Successful explo... |
| CVE-2026-76712 | HIGH | 7.3 | 0.4% | Sep 22, 2026 | A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized access, information di... |
| CVE-2026-76711 | HIGH | 7.5 | 0.5% | Sep 22, 2026 | A vulnerability exists in an Analytics and Location Engine (ALE) component where the impacted process improperly process... |
| CVE-2026-76710 | HIGH | 7.5 | 0.5% | Sep 22, 2026 | A vulnerability exists in the Analytics and Location Engine (ALE) management interface that may allow for the disclosure... |
| CVE-2026-76709 | CRITICAL | 9.8 | 0.6% | Sep 22, 2026 | A vulnerability exists in the internal administrative component of Analytics and Location Engine (ALE). Successful explo... |
| CVE-2026-76708 | CRITICAL | 9.8 | 0.6% | Sep 22, 2026 | A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operating system ... |
| CVE-2026-75432 | MEDIUM | 5.1 | 0.2% | Sep 22, 2026 | An issue in yaml-cpp 0.9.0 allows a remote attacker to obtain sensitive information via the src/scanner.cpp, Scanner::Po... |
| CVE-2026-65829 | MEDIUM | 5.3 | 0.4% | Sep 22, 2026 | MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 7.3.0 ... |
| CVE-2026-63628 | MEDIUM | 6.9 | 0.4% | Sep 22, 2026 | mppx is a TypeScript interface for machine payments protocol. Prior to 0.8.2, the fee-payer cosigning path in src/tempo/... |
| CVE-2026-63627 | MEDIUM | 6.9 | 0.5% | Sep 22, 2026 | mppx is a TypeScript interface for machine payments protocol. Prior to 0.8.2, FeePayerPolicy in src/tempo/internal/fee-p... |
| CVE-2026-63104 | HIGH | 8.1 | — | Sep 22, 2026 | Kaneo versions 2.3.12 before 2.12.2 contain a missing authorization vulnerability that allows authenticated workspace me... |
| CVE-2026-62985 | HIGH | 7.5 | 0.5% | Sep 22, 2026 | request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Prior ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now