2026 CVE Vulnerabilities
67,237 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-95661 | MEDIUM | 5.1 | — | Sep 22, 2026 | MISP contains a reflected cross-site scripting (XSS) vulnerability in the attribute histogram view. The $selectedTypes v... |
| CVE-2026-95659 | MEDIUM | 4.8 | — | Sep 22, 2026 | MISP contains a reflected cross-site scripting (XSS) vulnerability in the AnalystDataController::viewForObject action. T... |
| CVE-2026-95658 | MEDIUM | 6.9 | — | Sep 22, 2026 | MISP's WorkflowsController exposed the moduleStatelessExecution action in the Security component's unlockedActions list.... |
| CVE-2026-95619 | HIGH | 7.7 | — | Sep 22, 2026 | A flaw was found in libstdc++. An integer overflow can occur when processing large inputs to the aligned operator new in... |
| CVE-2026-95273 | MEDIUM | 4.3 | — | Sep 22, 2026 | A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7. This impacts the function static_content of ... |
| CVE-2026-95272 | LOW | 3.7 | — | Sep 22, 2026 | A vulnerability was found in dgtlmoon changedetection.io up to 0.60.7. This affects the function static_content of the f... |
| CVE-2026-95271 | HIGH | 7.3 | — | Sep 22, 2026 | A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The impacted element is the function check_a... |
| CVE-2026-93616 | CRITICAL | 9.8 | 2.4% | Sep 22, 2026 | A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary s... |
| CVE-2026-75791 | HIGH | 8.6 | — | Sep 22, 2026 | Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to an authentication bypass vulnerabi... |
| CVE-2026-95270 | LOW | 3.7 | — | Sep 22, 2026 | A flaw has been found in dgtlmoon changedetection.io up to 0.60.7. The affected element is the function check_password o... |
| CVE-2026-89420 | HIGH | 7.1 | — | Sep 22, 2026 | Improper Validation of Specified Quantity in Input in ZenHive mpp allows a client holding an open payment channel to obt... |
| CVE-2026-87119 | HIGH | 8.2 | — | Sep 22, 2026 | Authentication Bypass by Capture-replay in ZenHive mpp allows an attacker holding a captured subscription activation cre... |
| CVE-2026-74849 | CRITICAL | 9.8 | — | Sep 22, 2026 | Zohocorp ManageEngine ADSelfService Plus versions before build 7001 are vulnerable to a remote code execution vulnerabil... |
| CVE-2026-63279 | MEDIUM | 5.4 | — | Sep 22, 2026 | LibreOffice can import PICT images, which may be embedded in documents. An out of bounds read existed when importing an ... |
| CVE-2026-63278 | MEDIUM | 6.7 | — | Sep 22, 2026 | URLs could be constructed which expanded environment variable or INI file values, so potentially sensitive information c... |
| CVE-2026-63276 | MEDIUM | 5.4 | — | Sep 22, 2026 | LibreOffice converts CFF fonts to Type 1 when it subsets a font, which happens when a document is exported to PDF, and C... |
| CVE-2026-63275 | MEDIUM | 5.4 | — | Sep 22, 2026 | LibreOffice can read CFF fonts, which may be embedded in documents. A stack buffer overflow existed when reading the hin... |
| CVE-2026-63274 | MEDIUM | 5.4 | — | Sep 22, 2026 | LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing a stream object. The length of ... |
| CVE-2026-63273 | MEDIUM | 5.4 | — | Sep 22, 2026 | LibreOffice Draw can import PDF documents. A heap buffer overflow existed when importing an encrypted document. The leng... |
| CVE-2026-63272 | MEDIUM | 5.4 | — | Sep 22, 2026 | LibreOffice can import WMF graphics, which may be embedded in documents. A heap buffer overflow existed when importing a... |
| CVE-2026-95623 | MEDIUM | 5.6 | — | Sep 22, 2026 | The Tauri HTTP plugin validates requested URLs against the application's configured scope allowlist only once, on the in... |
| CVE-2026-92882 | MEDIUM | 5.3 | — | Sep 22, 2026 | Insufficiently protected credentials in the host and folder configuration endpoints of the REST API in Checkmk <2.5.0p15... |
| CVE-2026-90990 | MEDIUM | 5.3 | — | Sep 22, 2026 | Improper neutralization of newlines in filter values in the monitoring host and service list APIs in Checkmk <2.5.0p14 a... |
| CVE-2026-94117 | HIGH | 7.6 | — | Sep 22, 2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in DevItems HashBar –... |
| CVE-2026-90882 | HIGH | 8.7 | — | Sep 22, 2026 | The open-vsx.org deployment returned Access-Control-Allow-Origin reflecting the requesting origin together with Access-C... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now