2026 CVE Vulnerabilities
67,353 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93764 | MEDIUM | 6.5 | 0.1% | Sep 18, 2026 | Mongoid may omit encryption rules for fields declared on embedded models when generating the client-side field-level enc... |
| CVE-2026-93763 | MEDIUM | 6.5 | 0.2% | Sep 18, 2026 | A protection mechanism failure in the object-document mapper's encryption configuration generation can cause fields that... |
| CVE-2026-93762 | CRITICAL | 9.8 | 0.6% | Sep 18, 2026 | Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes... |
| CVE-2026-93761 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library ma... |
| CVE-2026-93760 | HIGH | 8.2 | 0.5% | Sep 18, 2026 | Mongoid does not restrict which query operators may come from caller-supplied filter data when an application hands that... |
| CVE-2026-93759 | HIGH | 8.6 | 0.4% | Sep 18, 2026 | Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the d... |
| CVE-2026-93753 | HIGH | 7.5 | 0.4% | Sep 18, 2026 | deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properl... |
| CVE-2026-93752 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | CSSOM through 0.5.0 contains a denial of service vulnerability in CSSStyleDeclaration.setProperty() that fails to valida... |
| CVE-2026-93751 | MEDIUM | 6.5 | 0.2% | Sep 18, 2026 | uri-js through 4.4.1 contains an improper UTF-8 decoding vulnerability in pctDecChars() that decodes invalid and overlon... |
| CVE-2026-93750 | MEDIUM | 5.9 | 0.4% | Sep 18, 2026 | http-cache-semantics through 4.2.0 contains a cache validation vulnerability in the _varyMatches() function that fails t... |
| CVE-2026-93749 | HIGH | 7.5 | 0.4% | Sep 18, 2026 | source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attacke... |
| CVE-2026-93748 | HIGH | 7.5 | 0.4% | Sep 18, 2026 | http-cache-semantics through 4.2.0 fails to properly validate security-zeroed cache entries when processing client max-s... |
| CVE-2026-93432 | MEDIUM | 6.1 | — | Sep 18, 2026 | A flaw was found in the Quarkus Qute template engine. When the {#eval} section helper processes a sub-template, it fails... |
| CVE-2026-92768 | MEDIUM | 5.5 | 0.1% | Sep 18, 2026 | A flaw was found in cockpit-machines. This vulnerability allows a local attacker to expose sensitive Virtual Machine (VM... |
| CVE-2026-92747 | MEDIUM | 5 | — | Sep 18, 2026 | A flaw was found in `cockpit-machines`. This vulnerability allows a local attacker with the ability to inspect running p... |
| CVE-2026-92745 | MEDIUM | 5 | 0.1% | Sep 18, 2026 | A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process met... |
| CVE-2026-92702 | CRITICAL | 9.1 | 0.3% | Sep 18, 2026 | Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions ... |
| CVE-2026-92701 | CRITICAL | 9.1 | 0.3% | Sep 18, 2026 | Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions ... |
| CVE-2026-91127 | HIGH | 8.2 | 0.4% | Sep 18, 2026 | File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applic... |
| CVE-2026-85058 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last W... |
| CVE-2026-84992 | MEDIUM | 6.1 | 0.3% | Sep 18, 2026 | md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt()... |
| CVE-2026-84975 | HIGH | 7.4 | 0.2% | Sep 18, 2026 | PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuT... |
| CVE-2026-81182 | MEDIUM | 4.2 | 0.3% | Sep 18, 2026 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a ... |
| CVE-2026-81181 | LOW | 3.7 | 0.2% | Sep 18, 2026 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for pro... |
| CVE-2026-81180 | HIGH | 8.8 | 0.4% | Sep 18, 2026 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Profess... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now