2026 CVE Vulnerabilities
64,755 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93265 | HIGH | 7.7 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: PCI/pwrctrl: tc9563: Fix parsing the integrated Eth... |
| CVE-2026-93262 | HIGH | 7.8 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: md/raid5-ppl: fix use-after-free in ppl_do_flush() ... |
| CVE-2026-93260 | HIGH | 7.4 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: powerpc/xive: propagate IPI init errors to prevent ... |
| CVE-2026-93250 | HIGH | 7.8 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: vxlan: mdb: Fix use-after-free in vxlan_mdb_flush()... |
| CVE-2026-93237 | HIGH | 7.8 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: LoongArch: Add DIRECT_MAP_PHYSMEM_END definition g... |
| CVE-2026-93229 | HIGH | 7.1 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: add missing read barrier to rpc_status_get du... |
| CVE-2026-93225 | HIGH | 7.4 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: phy: fsl-imx8mq-usb: fix typec switch leak on probe... |
| CVE-2026-93224 | HIGH | 8.1 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: svcrdma: Fix unmatched rn_unregister on failed acce... |
| CVE-2026-93221 | HIGH | 8.1 | — | Sep 24, 2026 | In the Linux kernel, the following vulnerability has been resolved: nfsd: convert nfsd_net boolean flags to unsigned lo... |
| CVE-2026-88369 | HIGH | 7.3 | 0.2% | Sep 24, 2026 | zserge jsmn commit 25647e6 is vulnerable to Buffer Overflow in example/jsondump.c dump(). |
| CVE-2026-88368 | HIGH | 7.5 | — | Sep 24, 2026 | NanoSVG commit 239e102ec contains an incorrect numeric conversion vulnerability in the rasterizer's nsvg__addActive() fu... |
| CVE-2026-88362 | HIGH | 7.5 | 0.2% | Sep 24, 2026 | MuJS e892c9fdb contains an incorrect numeric conversion vulnerability in jsR_isindex() in jsrun.c. A specially crafted J... |
| CVE-2026-88361 | HIGH | 7.5 | 0.2% | Sep 24, 2026 | SumatraPDF 3.6.1 contains an integer overflow vulnerability in EngineMupdf::BuildPageLabelRec() when parsing PDF PageLab... |
| CVE-2026-88357 | HIGH | 7.5 | — | Sep 24, 2026 | nDPI 5.1.0 contains a memory access issue in the DNS dissector and serializer deserialization code. Specially crafted ne... |
| CVE-2026-77581 | HIGH | 8.6 | — | Sep 24, 2026 | BentoPDF is a client-side PDF toolkit that is self hostable. In 2.8.6 and earlier, the certificate and timestamp CORS pr... |
| CVE-2026-75907 | HIGH | 7.5 | — | Sep 24, 2026 | The door access control on a Norwegian Cruise Line asset grants entry based only on the credential's static 7-byte UID s... |
| CVE-2026-63203 | HIGH | 7.6 | — | Sep 24, 2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. From 1.31.0 until 1.42.0, the Account API han... |
| CVE-2026-56739 | HIGH | 8.5 | — | Sep 24, 2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.43.0, Logto fetches administrator-... |
| CVE-2026-56737 | HIGH | 8.1 | — | Sep 24, 2026 | phpMyFAQ is an open source FAQ web application. Versions 3.2.0 through 4.1.5 contain an authentication bypass in its pub... |
| CVE-2026-97362 | HIGH | 7.5 | — | Sep 24, 2026 | HFS2 version 2.4.0 and earlier contains a denial of service vulnerability that allows unauthenticated attackers to cause... |
| CVE-2026-90959 | HIGH | 8.1 | 0.3% | Sep 24, 2026 | A path traversal vulnerability was found in pulpcore. The content upload API accepts a 'file_url' parameter that allows ... |
| CVE-2026-82094 | HIGH | 7.1 | — | Sep 24, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to traverse directories on the s... |
| CVE-2026-82093 | HIGH | 8.8 | — | Sep 24, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to... |
| CVE-2026-81552 | HIGH | 8.8 | — | Sep 24, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du... |
| CVE-2026-81548 | HIGH | 8.8 | 0.8% | Sep 24, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now