2026 CVE Vulnerabilities
67,468 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93488 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because... |
| CVE-2026-28199 | LOW | 3.3 | — | Sep 18, 2026 | An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underly... |
| CVE-2026-28198 | HIGH | 8.8 | — | Sep 18, 2026 | An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptograp... |
| CVE-2026-28197 | HIGH | 8.8 | — | Sep 18, 2026 | An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially cr... |
| CVE-2026-21806 | LOW | 3.1 | — | Sep 18, 2026 | HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows... |
| CVE-2026-93578 | MEDIUM | 5.9 | — | Sep 18, 2026 | A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSP... |
| CVE-2026-93575 | HIGH | 7.5 | 0.7% | Sep 18, 2026 | A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a ... |
| CVE-2026-93572 | HIGH | 7.5 | 0.6% | Sep 18, 2026 | A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sendin... |
| CVE-2026-93563 | HIGH | 7.5 | 0.6% | Sep 18, 2026 | A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-midd... |
| CVE-2026-93561 | MEDIUM | 6.5 | 0.3% | Sep 18, 2026 | A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and ... |
| CVE-2026-81627 | HIGH | 8.2 | 0.2% | Sep 18, 2026 | A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias rem... |
| CVE-2026-92976 | MEDIUM | 5.1 | — | Sep 18, 2026 | A stored Cross-Site Scripting (XSS) vulnerability in the profile management functionality of T-Systems’ TAO 2.0 suite. A... |
| CVE-2026-90884 | MEDIUM | 5.4 | — | Sep 18, 2026 | The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'notes' parameter in all v... |
| CVE-2026-87915 | HIGH | 7.2 | — | Sep 18, 2026 | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress ... |
| CVE-2026-87743 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | A flaw was found in Quarkus HTTP security. An unauthenticated attacker can exploit a discrepancy in how paths are normal... |
| CVE-2026-18405 | HIGH | 7.2 | — | Sep 18, 2026 | The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vul... |
| CVE-2026-15797 | MEDIUM | 6.4 | 0.4% | Sep 18, 2026 | The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popup Builder plugin for WordPress ... |
| CVE-2026-15579 | HIGH | 8.8 | — | Sep 18, 2026 | An out-of-bounds write vulnerability exists in some of the Ethernet switches because of improper validation of the usern... |
| CVE-2026-85410 | HIGH | 8.1 | 0.3% | Sep 18, 2026 | The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template... |
| CVE-2026-83561 | HIGH | 7.2 | — | Sep 18, 2026 | The Complianz GDPR/CCPA Cookie Consent Banner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comm... |
| CVE-2026-6205 | HIGH | 8.1 | — | Sep 18, 2026 | An external control of file name or path vulnerability in Upload API in Synology DiskStation Manager (DSM) before 7.2.1-... |
| CVE-2026-56597 | LOW | 3.1 | — | Sep 18, 2026 | HCL BigFix Service Management is affected by a Sensitive Information Leakage vulnerability, which could allow an unauthe... |
| CVE-2026-56595 | LOW | 3.1 | — | Sep 18, 2026 | HCL BigFix Service Management is affected by a CORS Misconfiguration vulnerability due to improperly validated origin he... |
| CVE-2026-56592 | MEDIUM | 6.5 | — | Sep 18, 2026 | HCL BigFix Service Management is affected by an Improper Authentication validation vulnerability related to inadequate a... |
| CVE-2026-56590 | MEDIUM | 6.4 | — | Sep 18, 2026 | HCL BigFix Service Management is affected by an Unrestricted File Upload vulnerability due to improper file validation c... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now