2026 CVE Vulnerabilities
64,760 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84355 | LOW | 3.1 | 0.2% | Sep 2, 2026 | Incorrect authorization in Navigation in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromi... |
| CVE-2026-84331 | LOW | 3.1 | 0.2% | Sep 2, 2026 | Incorrect authorization in Actor in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised t... |
| CVE-2026-84328 | LOW | 3.1 | 0.2% | Sep 2, 2026 | Missing authorization in FileSystem in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromise... |
| CVE-2026-84368 | LOW | 3.7 | 0.3% | Sep 1, 2026 | joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.6 and 18.2.5, the @hapi/... |
| CVE-2026-84367 | LOW | 3.7 | 0.3% | Sep 1, 2026 | joi is a schema description language and data validator for JavaScript. From 16.0.0 until 17.13.5 and 18.2.4, joi's lib/... |
| CVE-2026-84307 | LOW | 3.7 | 0.3% | Sep 1, 2026 | Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.12.5 and 5.7.5... |
| CVE-2026-73748 | LOW | 2.2 | 0.1% | Sep 1, 2026 | A vulnerability in the affected interface of HPE Networking Fabric Composer allows an attacker with administrative privi... |
| CVE-2026-73747 | LOW | 2.5 | 0.1% | Sep 1, 2026 | A local privilege-escalation vulnerability has been discovered in HPE Networking Fabric Composer. Successful exploitatio... |
| CVE-2026-73746 | LOW | 3.1 | 0.2% | Sep 1, 2026 | A denial-of-service vulnerability exists in the API of HPE Networking Fabric Composer that could allow an authenticated ... |
| CVE-2026-73745 | LOW | 3.1 | 0.2% | Sep 1, 2026 | A vulnerability in the API endpoint of HPE Networking Fabric Composer could allow an unauthenticated remote attacker to ... |
| CVE-2026-73744 | LOW | 3.5 | 0.2% | Sep 1, 2026 | A denial-of-service vulnerability exists in the web-based management interface of HPE Networking Fabric Composer that co... |
| CVE-2026-73743 | LOW | 3.7 | 0.1% | Sep 1, 2026 | A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated r... |
| CVE-2026-81846 | LOW | 3.5 | 0.2% | Sep 1, 2026 | An authorization bypass in the runZero Platform MCP service has been resolved in version 5.1.260826.0. This issue is an ... |
| CVE-2026-52295 | LOW | 2.9 | 0.1% | Sep 1, 2026 | FFmpeg before 9.0 has an out-of-bounds read because the copied extradata lacked required padding before GetBitContext-ba... |
| CVE-2026-82748 | LOW | 2.1 | 0.1% | Sep 1, 2026 | Incorrect Authorization vulnerability in ash-project ash authorizes an aggregate under one read action while computing i... |
| CVE-2026-82744 | LOW | 2.1 | 0.1% | Sep 1, 2026 | Not Failing Securely (Failing Open) vulnerability in ash-project ash skips an Ash.Reactor change when the guard controll... |
| CVE-2026-82743 | LOW | 2.1 | 0.1% | Sep 1, 2026 | Uncontrolled Resource Consumption vulnerability in ash-project ash lets a slow asynchronous read spin a scheduler thread... |
| CVE-2026-82741 | LOW | 2.1 | 0.1% | Sep 1, 2026 | Improper Validation of Specified Type of Input vulnerability in ash-project ash lets an attacker confuse the stored type... |
| CVE-2026-82740 | LOW | 2.1 | 0.1% | Sep 1, 2026 | Improper Input Validation vulnerability in ash-project ash fails to enforce the outer array constraints on a doubly-nest... |
| CVE-2026-82739 | LOW | 2.1 | 0.1% | Sep 1, 2026 | Generation of Error Message Containing Sensitive Information vulnerability in ash-project ash discloses the stored value... |
| CVE-2026-82736 | LOW | 2.1 | 0.1% | Sep 1, 2026 | Incorrect Behavior Order: Validate Before Canonicalize vulnerability in ash-project ash lets an attacker store a case-in... |
| CVE-2026-82734 | LOW | 2.1 | 0.1% | Sep 1, 2026 | Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to submit a non-f... |
| CVE-2026-82731 | LOW | 2.3 | 0.3% | Sep 1, 2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in ash-project ash_typescript allows an attacker who c... |
| CVE-2026-48932 | LOW | 3.7 | 0.2% | Sep 1, 2026 | A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild ou... |
| CVE-2026-18743 | LOW | 2.5 | 0.1% | Sep 1, 2026 | A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now