2026 CVE Vulnerabilities
67,227 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-43643 | HIGH | 7.5 | — | Sep 22, 2026 | Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an authorization bypass vulnerability in the billing m... |
| CVE-2026-43642 | HIGH | 8.1 | 1.0% | Sep 22, 2026 | Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains a PHP object injection vulnerability in the billing mo... |
| CVE-2026-43641 | CRITICAL | 9.8 | 3.0% | Sep 22, 2026 | Softaculous Virtualizor before 3.2.9 (Patch 9) and 3.0.0 contains an OS command injection vulnerability in the billing m... |
| CVE-2026-18626 | MEDIUM | 6.8 | — | Sep 22, 2026 | Out-of-bounds Read vulnerability in RTI Connext Professional (Core Libraries) allows Overread Buffers. This issue affect... |
| CVE-2026-18462 | HIGH | 7.3 | — | Sep 22, 2026 | Integer Overflow or Wraparound, Improper Access Control vulnerability in RTI Connext Professional (Core Libraries) allow... |
| CVE-2026-18461 | CRITICAL | 9.2 | — | Sep 22, 2026 | Use of Externally-Controlled Format String vulnerability in RTI Connext Professional (Core Libraries) allows Format Stri... |
| CVE-2026-18460 | MEDIUM | 6.9 | — | Sep 22, 2026 | Off-by-one Error, Out-of-bounds Write vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers... |
| CVE-2026-18459 | HIGH | 8.7 | — | Sep 22, 2026 | Incorrect Calculation vulnerability in RTI Connext Professional (Core Libraries) allows Abuse Existing Functionality. Th... |
| CVE-2026-18458 | MEDIUM | 6.8 | — | Sep 22, 2026 | Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type ... |
| CVE-2026-18457 | HIGH | 8.3 | — | Sep 22, 2026 | Heap-based Buffer Overflow vulnerability in RTI Connext Professional (Core Libraries) allows Overflow Buffers. This issu... |
| CVE-2026-11389 | MEDIUM | 6.8 | — | Sep 22, 2026 | Out-of-bounds Read, Function Call With Incorrect Number of Arguments, Access of Resource Using Incompatible Type ('Type ... |
| CVE-2026-11388 | MEDIUM | 6.9 | — | Sep 22, 2026 | Double Free vulnerability in RTI Connext Professional (Core Libraries) allows File Manipulation. This issue affects Conn... |
| CVE-2026-95818 | LOW | 3.6 | — | Sep 22, 2026 | A stack-based buffer overflow in the dynamic loader (ld.so) of the GNU C Library (glibc) versions 2.14 through 2.44 allo... |
| CVE-2026-94456 | CRITICAL | 9.1 | — | Sep 22, 2026 | Postiz generates security-sensitive credentials using `Math.random()` instead of a cryptographically secure source. The ... |
| CVE-2026-94455 | HIGH | 7.1 | — | Sep 22, 2026 | An HTTP endpoint intended for provisioning enterprise and reseller organisations is reachable without any session. The a... |
| CVE-2026-87902 | HIGH | 8.1 | 18.2% | Sep 22, 2026 | An unauthenticated attacker can make `get_page_template()` page-template resolution include a chosen readable local `.ph... |
| CVE-2026-86062 | MEDIUM | 6.1 | — | Sep 22, 2026 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, lightrag_webui/src/components/retrieva... |
| CVE-2026-86059 | CRITICAL | 9.6 | — | Sep 22, 2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy organization members without Gi... |
| CVE-2026-85740 | HIGH | 7.1 | — | Sep 22, 2026 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, _validated_addresses in lightrag/parse... |
| CVE-2026-85734 | CRITICAL | 9.1 | — | Sep 22, 2026 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the POST /login endpoint in lightrag/a... |
| CVE-2026-85725 | MEDIUM | 5.9 | 0.4% | Sep 22, 2026 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, verify_password in lightrag/api/passwo... |
| CVE-2026-85709 | MEDIUM | 5.3 | — | Sep 22, 2026 | LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.5, the LightRAG API server returns raw Py... |
| CVE-2026-84301 | MEDIUM | 6.3 | 0.4% | Sep 22, 2026 | FastGPT is an open-source LLM platform for building AI applications on a knowledge base. Prior to 4.15.2, the safe Axios... |
| CVE-2026-83803 | HIGH | 7.7 | 0.6% | Sep 22, 2026 | Sentry is an error tracking and performance monitoring tool. From 23.11.0 until 26.7.0, Sentry instances with the reloca... |
| CVE-2026-83603 | HIGH | 8.4 | 0.3% | Sep 22, 2026 | Netdata is an open source observability tool. Prior to 2.10.4, the setuid-root ndsudo helper command fail2ban-client-sta... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now