2026 CVE Vulnerabilities
67,413 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-92745 | MEDIUM | 5 | 0.1% | Sep 18, 2026 | A flaw was found in cockpit-machines. This vulnerability allows a local attacker with the ability to inspect process met... |
| CVE-2026-92702 | CRITICAL | 9.1 | 0.3% | Sep 18, 2026 | Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions ... |
| CVE-2026-92701 | CRITICAL | 9.1 | 0.3% | Sep 18, 2026 | Cocos AI is a confidential computing system for running AI workloads inside trusted execution environments. In versions ... |
| CVE-2026-91127 | HIGH | 8.2 | 0.4% | Sep 18, 2026 | File Viewer is a browser-native viewer for Office, PDF, CAD, archive, and other files in private and internal web applic... |
| CVE-2026-85058 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client-controlled Last W... |
| CVE-2026-84992 | MEDIUM | 6.1 | 0.3% | Sep 18, 2026 | md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and TypeScript. Prior to 6.5.4, MdPreview's useMarkdownIt()... |
| CVE-2026-84975 | HIGH | 7.4 | 0.2% | Sep 18, 2026 | PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the OpenSSL and GnuT... |
| CVE-2026-81182 | MEDIUM | 4.2 | 0.3% | Sep 18, 2026 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, an unauthenticated attacker who holds a ... |
| CVE-2026-81181 | LOW | 3.7 | 0.2% | Sep 18, 2026 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.68, the password authentication flow for pro... |
| CVE-2026-81180 | HIGH | 8.8 | 0.4% | Sep 18, 2026 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Profess... |
| CVE-2026-81179 | HIGH | 8.1 | — | Sep 18, 2026 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.58, installations that enable password reset... |
| CVE-2026-81178 | LOW | 3.5 | — | Sep 18, 2026 | SysReptor is a fully customizable pentest reporting platform. Prior to 2026.55, an unauthenticated holder of a public no... |
| CVE-2026-77396 | MEDIUM | 6.9 | 0.2% | Sep 18, 2026 | PJSIP is a free and open source multimedia communication library written in C. In 2.17 and earlier, the PJSIP AVI parser... |
| CVE-2026-77386 | MEDIUM | 6.5 | 0.6% | Sep 18, 2026 | Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, an unauthenticated attacker cou... |
| CVE-2026-77385 | MEDIUM | 4.3 | 0.3% | Sep 18, 2026 | Kyoo is a self-hosted media server focused on movies, series, and anime. Prior to 5.1.0, a registered user with the core... |
| CVE-2026-71537 | MEDIUM | 6.5 | 0.3% | Sep 18, 2026 | Paymenter is a free and open-source webshop solution for management of hosting services. Prior to 1.5.7, app/Livewire/Se... |
| CVE-2026-69186 | MEDIUM | 5.3 | 0.5% | Sep 18, 2026 | c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_parse() trusts the attacker-controlled ANCOUNT, NS... |
| CVE-2026-69184 | HIGH | 7.5 | 0.7% | Sep 18, 2026 | c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression poi... |
| CVE-2026-64847 | MEDIUM | 6.8 | 0.2% | Sep 18, 2026 | AnyIO is a high level asynchronous concurrency and networking framework that works on top of either Trio or asyncio. Pri... |
| CVE-2026-63458 | HIGH | 7.1 | 0.3% | Sep 18, 2026 | Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-beta.3, an authenti... |
| CVE-2026-63445 | HIGH | 7.1 | 0.8% | Sep 18, 2026 | Perses is an open-source dashboard and visualization project for observability data. Prior to 0.54.0-rc.0, list endpoint... |
| CVE-2026-63199 | HIGH | 8.3 | 0.3% | Sep 18, 2026 | Perses is an open-source dashboard and visualization project for observability data. From 0.43.0 until 0.54.0-rc.0, the ... |
| CVE-2026-62279 | HIGH | 7.1 | 0.4% | Sep 18, 2026 | LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, an aut... |
| CVE-2026-62278 | HIGH | 8.1 | 0.5% | Sep 18, 2026 | LubeLogger is a self-hosted, open-source, web-based vehicle maintenance and fuel mileage tracker. Prior to 1.6.8, authen... |
| CVE-2026-61552 | HIGH | 7.2 | 0.9% | Sep 18, 2026 | Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes atta... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now