2026 CVE Vulnerabilities
67,274 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86553 | HIGH | 8.8 | 0.4% | Sep 20, 2026 | SmartLife app dynamically generates fresh SmartLife application authentication parameters inside its runtime process. Us... |
| CVE-2026-86552 | MEDIUM | 5.4 | 0.3% | Sep 20, 2026 | SmartLife app dynamically generates brand‑new SmartLife application authentication parameters at runtime. With the acqui... |
| CVE-2026-93959 | HIGH | 7.3 | 0.4% | Sep 20, 2026 | A vulnerability was determined in SourceCodester Online Reviewer Management System 1.0. This issue affects some unknown ... |
| CVE-2026-94084 | CRITICAL | 9.4 | — | Sep 20, 2026 | Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.r... |
| CVE-2026-94083 | CRITICAL | 9.4 | — | Sep 20, 2026 | Suricata before 8.0.7 has a DoH2 type confusion that can cause an invalid free, because cleanup code for the HTTP2 state... |
| CVE-2026-93958 | CRITICAL | 9.1 | 2.2% | Sep 20, 2026 | A vulnerability was found in D-Link R95 BE9500_1.00.16. This vulnerability affects the function system of the file /bin/... |
| CVE-2026-93957 | MEDIUM | 4.3 | 0.3% | Sep 20, 2026 | A vulnerability has been found in olivier-ls PHP-FTS up to 1.1.3. This affects the function SearchEngine::matchesSingleF... |
| CVE-2026-86551 | LOW | 3.3 | 0.2% | Sep 20, 2026 | The Z80Ultra (NX741J) product contains a vulnerability where non-privileged programs can retrieve the Wi-Fi MAC address ... |
| CVE-2026-94057 | MEDIUM | 5.3 | 0.3% | Sep 19, 2026 | Exim before 4.100.1 allows SMTP smuggling in which the received message does not match any sent message, and instead dep... |
| CVE-2026-94056 | HIGH | 7.5 | 0.4% | Sep 19, 2026 | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, allows attackers to read certain uni... |
| CVE-2026-94055 | MEDIUM | 5.3 | 0.4% | Sep 19, 2026 | Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free. |
| CVE-2026-94054 | MEDIUM | 5.3 | 0.3% | Sep 19, 2026 | Exim before 4.100.1, when Proxy-Protocol is used with an attacker-controlled proxy, has an out-of-bounds write. |
| CVE-2026-93993 | HIGH | 8.8 | 0.6% | Sep 19, 2026 | Mistral Vibe before 2.25.5 contains a remote code execution vulnerability in the worktree creation process that executes... |
| CVE-2026-93992 | HIGH | 8.1 | 0.8% | Sep 19, 2026 | Gopeed through 2.0.0-beta.3 contains a path traversal vulnerability in archive extraction that allows attackers to write... |
| CVE-2026-93991 | HIGH | 7.7 | 0.3% | Sep 19, 2026 | Argo Workflows versions 4.1.0 through 4.1.3 contain an authorization bypass vulnerability in ListArchivedWorkflows that ... |
| CVE-2026-93990 | HIGH | 7.5 | — | Sep 19, 2026 | Expat before 2.8.5 fails to validate that a high surrogate in UTF-16 input is followed by a low surrogate, allowing malf... |
| CVE-2026-93989 | MEDIUM | 4.3 | — | Sep 19, 2026 | vLLM through 0.29.0 fails to properly validate bad_words token indices against the model's generation output width in Sa... |
| CVE-2026-93988 | MEDIUM | 6.5 | 0.4% | Sep 19, 2026 | QloApps through 1.7.0 contains a path traversal vulnerability in the getEmailHTML action of admin/ajax.php that allows a... |
| CVE-2026-93956 | LOW | 3.5 | 0.2% | Sep 19, 2026 | A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by this issue is the function SearchEngine::buildHighl... |
| CVE-2026-93955 | MEDIUM | 4.3 | 0.4% | Sep 19, 2026 | A vulnerability was detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected by this vulnerability is the functio... |
| CVE-2026-89155 | — | — | — | Sep 19, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-93954 | MEDIUM | 4.3 | 0.4% | Sep 19, 2026 | A security vulnerability has been detected in grimmory-tools grimmory up to 3.3.3/3.4.1. Affected is the function AppSet... |
| CVE-2026-82672 | MEDIUM | 6.3 | 0.3% | Sep 19, 2026 | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint mint allow... |
| CVE-2026-82560 | HIGH | 7.5 | 0.6% | Sep 19, 2026 | Pod::Text versions before 6.1.1 for Perl allow CPU and memory exhaustion formatting a POD document whose =over nesting d... |
| CVE-2026-94001 | MEDIUM | 6.5 | 0.3% | Sep 19, 2026 | A flaw was found in the Admin REST API of Keycloak, an open-source identity and access management solution. The endpoint... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now