2026 CVE Vulnerabilities
67,237 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-65121 | CRITICAL | 9.8 | 0.3% | Sep 22, 2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentic... |
| CVE-2026-65118 | CRITICAL | 9.8 | 0.1% | Sep 22, 2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate v... |
| CVE-2026-65117 | HIGH | 8.8 | 0.2% | Sep 22, 2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of a hard-coded pa... |
| CVE-2026-65115 | MEDIUM | 6.5 | 0.5% | Sep 22, 2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker may cause uncontrolled resource co... |
| CVE-2026-65114 | CRITICAL | 9.8 | 0.4% | Sep 22, 2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause missing authentication... |
| CVE-2026-65113 | CRITICAL | 9.8 | 0.6% | Sep 22, 2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded cred... |
| CVE-2026-65112 | MEDIUM | 6.5 | 0.5% | Sep 22, 2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause uncontrolled resource ... |
| CVE-2026-65111 | HIGH | 7.8 | 0.2% | Sep 22, 2026 | NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an attacker could cause a... |
| CVE-2026-24267 | HIGH | 7.8 | 0.3% | Sep 22, 2026 | NVIDIA NeMo Speech for all platforms contains a vulnerability in the speech data explorer component, where malicious dat... |
| CVE-2026-24239 | HIGH | 7.8 | 0.3% | Sep 22, 2026 | NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious data created by an attacker could cause re... |
| CVE-2026-19915 | HIGH | 7.3 | 0.1% | Sep 22, 2026 | A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.55.10.0. The ... |
| CVE-2026-95682 | MEDIUM | 4.8 | — | Sep 22, 2026 | MISP contains a stored cross-site scripting (XSS) vulnerability in the admin email composition screen. The MISP.org orga... |
| CVE-2026-95679 | MEDIUM | 6.9 | — | Sep 22, 2026 | MISP's RequestHandlerComponent automatically decodes XML request bodies on all write requests. The underlying Xml::build... |
| CVE-2026-95675 | CRITICAL | 9.8 | — | Sep 22, 2026 | D-Link DAP-1360 firmware version 6.14 and earlier contains an unauthenticated remote code execution vulnerability that a... |
| CVE-2026-95674 | MEDIUM | 5.3 | — | Sep 22, 2026 | In MISP, the queryEnrichment method in EventsController.php accepted a module name parameter and iterated over the list ... |
| CVE-2026-95671 | MEDIUM | 5.3 | — | Sep 22, 2026 | In MISP, the CollectionsController add() method enforced the sharing-group usability authorization check and element cap... |
| CVE-2026-95667 | MEDIUM | 6.9 | — | Sep 22, 2026 | The MISP installer scripts (for Debian 12, Debian 13, Ubuntu 24.04, and RHEL 9.4) create a log file at /var/log/misp_ins... |
| CVE-2026-95666 | MEDIUM | 4.3 | — | Sep 22, 2026 | Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to limit the length o... |
| CVE-2026-95665 | MEDIUM | 5.1 | — | Sep 22, 2026 | MISP contains a reflected cross-site scripting (XSS) vulnerability in the event REST search export confirmation form. Th... |
| CVE-2026-95499 | HIGH | 7.3 | — | Sep 22, 2026 | A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_u... |
| CVE-2026-95396 | MEDIUM | 4.3 | 0.5% | Sep 22, 2026 | A vulnerability was identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is an unk... |
| CVE-2026-93343 | MEDIUM | 6.5 | 0.4% | Sep 22, 2026 | MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_admin_ven... |
| CVE-2026-93342 | MEDIUM | 5.4 | 0.3% | Sep 22, 2026 | MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_duplicate... |
| CVE-2026-93341 | MEDIUM | 4.3 | — | Sep 22, 2026 | MarketKing plugin for WordPress before 2.1.72 contains a missing authorization vulnerability in the marketking_send_refu... |
| CVE-2026-12718 | CRITICAL | 9.8 | — | Sep 22, 2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Karel Electronic I... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now