2026 CVE Vulnerabilities
64,760 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-76087 | HIGH | 8.2 | — | Sep 23, 2026 | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's anonymous formie/submissions/submi... |
| CVE-2026-76086 | HIGH | 8.5 | — | Sep 23, 2026 | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.23 and 3.1.31, Formie's formie/integrations/form-settings ... |
| CVE-2026-75131 | HIGH | 7.8 | 0.2% | Sep 23, 2026 | NetworkManager-l2tp through 1.52.4, fixed in 1.52.6, contains a privilege escalation vulnerability that allows local use... |
| CVE-2026-61814 | HIGH | 7.5 | — | Sep 23, 2026 | Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's AsyncParser can perform quadratic work when a single JSON tok... |
| CVE-2026-61695 | HIGH | 7.5 | — | Sep 23, 2026 | Wire provides gRPC and protocol buffers for Android, Kotlin, Swift, and Java. Prior to 6.4.1 and 7.0.0-alpha04, Wire's S... |
| CVE-2026-59990 | HIGH | 7.5 | — | Sep 23, 2026 | Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods accept arbitrarily deep JSON array and object nes... |
| CVE-2026-91775 | HIGH | 7.4 | — | Sep 23, 2026 | LimeSurvey fails to safely encode attacker-controlled content from a crafted .lss survey file when displaying import war... |
| CVE-2026-86938 | HIGH | 7.3 | 0.1% | Sep 23, 2026 | A DLL hijacking vulnerability in the FileMaker Pro installer for Windows allowed a local user to execute arbitrary code ... |
| CVE-2026-86926 | HIGH | 7.8 | 0.2% | Sep 23, 2026 | A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously... |
| CVE-2026-96808 | HIGH | 7.4 | 0.1% | Sep 23, 2026 | In Flatpak before 1.18.1, the revokefs writer, used by the flatpak-system-helper to receive repository data from unprivi... |
| CVE-2026-96804 | HIGH | 8.8 | — | Sep 23, 2026 | MLflow's statsmodel flavor, versions 2.1.0 to 3.14.0, omits the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security contr... |
| CVE-2026-96775 | HIGH | 8.8 | — | Sep 23, 2026 | MLflow's dspy flavor, versions >= 2.0, applies the MLFLOW_ALLOW_PICKLE_DESERIALIZATION=False security control only when... |
| CVE-2026-96756 | HIGH | 8.1 | — | Sep 23, 2026 | orval versions before 8.30.0 contain a code injection vulnerability in the @orval/core factory generator that fails to e... |
| CVE-2026-96656 | HIGH | 7.2 | — | Sep 23, 2026 | Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary files that may be executed on load. The pr... |
| CVE-2026-96514 | HIGH | 7.3 | — | Sep 23, 2026 | A weakness has been identified in Neethuharii CafeManagement. Impacted is an unknown function of the file CafePortalLogi... |
| CVE-2026-96513 | HIGH | 7.3 | — | Sep 23, 2026 | A security flaw has been discovered in Neethuharii CafeManagement. This issue affects some unknown processing of the fil... |
| CVE-2026-95847 | HIGH | 8.8 | — | Sep 23, 2026 | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, H2PersistentQueue derives a session's message-map name as q... |
| CVE-2026-95846 | HIGH | 7.5 | 0.3% | Sep 23, 2026 | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.publishWill publishes a client's Last-Will messa... |
| CVE-2026-95845 | HIGH | 7.5 | 0.3% | Sep 23, 2026 | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, the broker does not enforce a maximum length for pending pe... |
| CVE-2026-95844 | HIGH | 8.7 | — | Sep 23, 2026 | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, Moquette does not limit the depth of topic names and topic ... |
| CVE-2026-95843 | HIGH | 7.5 | 0.4% | Sep 23, 2026 | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, PostOffice.subscribe parses a shared-subscription filter th... |
| CVE-2026-95842 | HIGH | 7.5 | 0.4% | Sep 23, 2026 | Moquette is a lightweight Java MQTT broker. Prior to 0.18.1, SessionEventLoop.run catches only InterruptedException, and... |
| CVE-2026-93349 | HIGH | 8.8 | 2.0% | Sep 23, 2026 | Frictionless through 5.20.0rc1 contains an OS command injection vulnerability in the explore console command that allows... |
| CVE-2026-88832 | HIGH | 7.3 | 0.1% | Sep 23, 2026 | BusyBox romfs volume ID parsing uses unbounded strlen on attacker-controlled metadata, causing a heap buffer overflow wh... |
| CVE-2026-88830 | HIGH | 7.5 | — | Sep 23, 2026 | A unit confusion in BusyBox TLS Montgomery reduction buffer allocation causes a pre-authentication heap buffer overflow ... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now