2026 CVE Vulnerabilities
64,760 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-81548 | HIGH | 8.8 | 0.8% | Sep 24, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du... |
| CVE-2026-81547 | HIGH | 8.8 | — | Sep 24, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du... |
| CVE-2026-81545 | HIGH | 8.8 | — | Sep 24, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du... |
| CVE-2026-81539 | HIGH | 8.8 | — | Sep 24, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to... |
| CVE-2026-77874 | HIGH | 8.6 | — | Sep 24, 2026 | IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL injection.... |
| CVE-2026-58008 | HIGH | 8.1 | — | Sep 24, 2026 | Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured... |
| CVE-2026-58007 | HIGH | 8.1 | — | Sep 24, 2026 | Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configur... |
| CVE-2026-58006 | HIGH | 8.1 | — | Sep 24, 2026 | Untrusted pointer dereference vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configur... |
| CVE-2026-58005 | HIGH | 8.1 | — | Sep 24, 2026 | Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS allows Privilege Escalation and Overflow Buffers. Th... |
| CVE-2026-58004 | HIGH | 8.1 | — | Sep 24, 2026 | Out-of-bounds read vulnerability in Altera Trusted Firmware on HPS allows Privilege Escalation and Overflow Buffers. Th... |
| CVE-2026-56736 | HIGH | 8.2 | — | Sep 24, 2026 | phpMyFAQ is an open source FAQ web application. A stored cross-site scripting (XSS) vulnerability in versions prior to 4... |
| CVE-2026-51997 | HIGH | 8.8 | 0.3% | Sep 24, 2026 | An issue in geelen mcp-remote 0.1.16 through 0.1.38 allows a remote attacker to execute arbitrary code via the open() fu... |
| CVE-2026-51995 | HIGH | 7.5 | — | Sep 24, 2026 | An issue in geelen mcp-remote 0.1.32 through 0.1.38 allows a remote attacker to obtain sensitive information via the src... |
| CVE-2026-13467 | HIGH | 8.1 | — | Sep 24, 2026 | Out-of-bounds write vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured or Impl... |
| CVE-2026-13466 | HIGH | 8.1 | — | Sep 24, 2026 | Incorrect calculation of buffer size vulnerability in Altera Trusted Firmware on HPS allows Overflow Buffers. This issu... |
| CVE-2026-13465 | HIGH | 8.1 | — | Sep 24, 2026 | Stack-based buffer overflow vulnerability in Altera Trusted Firmware on HPS allows Exploitation of Improperly Configured... |
| CVE-2026-12559 | HIGH | 7.3 | — | Sep 24, 2026 | A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solu... |
| CVE-2026-97059 | HIGH | 8.2 | — | Sep 24, 2026 | DCMTK through 3.7.0 contains a heap over-read vulnerability in ConcatenationLoader that copies pixel data frames without... |
| CVE-2026-97057 | HIGH | 7.5 | — | Sep 24, 2026 | redis-parser through 3.0.0 fails to validate the multi-bulk length value in RESP protocol parsing, allowing attackers to... |
| CVE-2026-95521 | HIGH | 7.8 | — | Sep 24, 2026 | A command injection flaw was found in rpm. Installing or rebuilding a source RPM whose source or spec file basenames con... |
| CVE-2026-95519 | HIGH | 7.8 | — | Sep 24, 2026 | A flaw was found in rpm. An attacker can supply a crafted manifest file that, when processed by a user or automation usi... |
| CVE-2026-97182 | HIGH | 7.3 | — | Sep 24, 2026 | A security vulnerability has been detected in halo-dev Halo up to 2.25.4/2.26.1. Affected is an unknown function of the ... |
| CVE-2026-96515 | HIGH | 8.6 | — | Sep 24, 2026 | This vulnerability exists in the Netlink ICT HG323RW router due to insufficient authorization and input validation contr... |
| CVE-2026-88907 | HIGH | 7.4 | — | Sep 24, 2026 | Incorrect Authorization vulnerability in TÜBİTAK ULAKBİM UlakPDF allows Authentication Bypass. This issue affects UlakP... |
| CVE-2026-7169 | HIGH | 7.5 | — | Sep 24, 2026 | a vulnerability involving an unchecked search path element in Evope Collector, versions prior to 1.1.7.13, allows a loca... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now