2026 CVE Vulnerabilities
67,446 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93653 | MEDIUM | 5.5 | — | Sep 18, 2026 | A denial of service flaw was found in Poppler's Splash backend. A crafted PDF with tiling-pattern geometry approaching t... |
| CVE-2026-93652 | HIGH | 7.5 | — | Sep 18, 2026 | Integer overflow in µD3TN v0.15.0 TCPCLv3 handshake causes heap overflow, allowing remote attackers to reliably cause Do... |
| CVE-2026-93576 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | A flaw was found in Netty netty-codec-smtp. The component does not properly validate Carriage Return (CR) and Line Feed ... |
| CVE-2026-93573 | MEDIUM | 6.5 | 0.3% | Sep 18, 2026 | A flaw was found in Netty's HTTP/1.1 decoder. This vulnerability allows a remote attacker to bypass `Transfer-Encoding` ... |
| CVE-2026-93569 | HIGH | 8.2 | 0.5% | Sep 18, 2026 | A flaw was found in Netty. A remote unauthenticated attacker can exploit a vulnerability in Netty's HTTP/1 to HTTP/2 con... |
| CVE-2026-93568 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | A flaw was found in Netty. A remote attacker could exploit this vulnerability by sending specially crafted HTTP/2 or HTT... |
| CVE-2026-93567 | HIGH | 7.5 | 0.6% | Sep 18, 2026 | A flaw was found in Netty's HTTP/2 codec. When converting HTTP/1 CONNECT requests to HTTP/2, the component incorrectly u... |
| CVE-2026-93566 | MEDIUM | 6.5 | 0.5% | Sep 18, 2026 | A flaw was found in Netty. A remote attacker could exploit this by sending a specially crafted HTTP request that include... |
| CVE-2026-93565 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | A flaw was found in Netty RtspDecoder. The `RtspMethods.valueOf()` function incorrectly strips trailing control bytes fr... |
| CVE-2026-93564 | HIGH | 7.5 | 0.6% | Sep 18, 2026 | A flaw was found in Netty. A reference-count leak in the HAProxy PROXY-v2 message decoder allows a remote, unauthenticat... |
| CVE-2026-93558 | HIGH | 7.5 | 0.7% | Sep 18, 2026 | A flaw was found in Netty's WebSocketServerExtensionHandler. A remote, unauthenticated attacker can exploit this vulnera... |
| CVE-2026-93506 | MEDIUM | 6.3 | 0.4% | Sep 18, 2026 | A vulnerability was determined in SveltyCMS 0.0.6. This issue affects some unknown processing of the file /mediagallery/... |
| CVE-2026-93505 | LOW | 3.5 | — | Sep 18, 2026 | A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-... |
| CVE-2026-85511 | MEDIUM | 4.2 | 0.3% | Sep 18, 2026 | A flaw was found in EAP's Elytron. An EAP application whose security domain is backed by an Elytron token-realm with oau... |
| CVE-2026-77929 | HIGH | 8.8 | 0.5% | Sep 18, 2026 | ClipBucket v5 before 5.5.3-#182 contains a file upload vulnerability that allows authenticated users to achieve remote c... |
| CVE-2026-77928 | MEDIUM | 6.5 | 0.3% | Sep 18, 2026 | ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract ... |
| CVE-2026-77927 | MEDIUM | 6.5 | 0.4% | Sep 18, 2026 | ClipBucket v5 before 5.5.3-#182 contains a blind SQL injection vulnerability that allows authenticated users to extract ... |
| CVE-2026-25684 | MEDIUM | 4.4 | — | Sep 18, 2026 | A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluatio... |
| CVE-2026-16515 | MEDIUM | 4.7 | — | Sep 18, 2026 | net_icmpv6_send_error() in subsys/net/ip/icmpv6.c implemented only one of the three RFC 4443 section 2.4 suppression rul... |
| CVE-2026-16514 | MEDIUM | 4.3 | — | Sep 18, 2026 | gptp_mi_qualify_announce() in subsys/net/l2/ethernet/gptp/gptp_mi.c walks the Path Trace TLV of a received IEEE 802.1AS ... |
| CVE-2026-16512 | LOW | 3.1 | — | Sep 18, 2026 | gptp_handle_msg() in subsys/net/l2/ethernet/gptp/gptp.c dereferenced the gPTP header returned by GPTP_HDR() and switched... |
| CVE-2026-10832 | MEDIUM | 5.9 | — | Sep 18, 2026 | A flaw was found in the DERDecoder class within wildfly-elytron-asn1. A remote attacker can exploit this resource exhaus... |
| CVE-2026-93606 | CRITICAL | 10 | — | Sep 18, 2026 | vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape in `VM` and `NodeVM`. When an embedder exposes a host API... |
| CVE-2026-93605 | CRITICAL | 10 | 0.4% | Sep 18, 2026 | vm2 NodeVM versions before 3.12.1 contain a sandbox escape vulnerability where the DANGEROUS_BUILTINS denylist omits chi... |
| CVE-2026-93604 | HIGH | 7.2 | — | Sep 18, 2026 | vm2 through 3.12.0 exposes Node.js's crypto.setFips() function to untrusted guest code when an embedder explicitly allow... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now