2026 CVE Vulnerabilities
68,107 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-93589 | LOW | 3.7 | 0.3% | Sep 18, 2026 | ImageMagick before 7.1.2-31 and 6.9.13-56 contains a division-by-zero flaw in the FLIF encoder. An incorrect value for t... |
| CVE-2026-93588 | LOW | 3.1 | 0.3% | Sep 18, 2026 | ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a NULL pointer dereference in the PNM coder. When the coder re... |
| CVE-2026-93587 | LOW | 3.3 | 0.1% | Sep 18, 2026 | ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD (and, per the upstream advisory, CU... |
| CVE-2026-93586 | LOW | 2.9 | 0.1% | Sep 18, 2026 | ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, cau... |
| CVE-2026-93560 | HIGH | 7.5 | 0.4% | Sep 18, 2026 | A flaw was found in the Netty STOMP codec. A remote attacker could send a specially crafted STOMP frame with a content-l... |
| CVE-2026-93504 | MEDIUM | 6.3 | 0.4% | Sep 18, 2026 | A vulnerability has been found in SveltyCMS 0.0.6. This affects an unknown part of the file src/routes/api/[...path]/+se... |
| CVE-2026-93019 | CRITICAL | 9.1 | — | Sep 18, 2026 | Imager versions before 1.036 for Perl exit the process reading a TGA with a colour map length of 32768 or more in tga_pa... |
| CVE-2026-93018 | MEDIUM | 5.5 | 0.2% | Sep 18, 2026 | Imager versions before 1.036 for Perl disclose uninitialised heap memory reading a paletted image with pixel indexes pas... |
| CVE-2026-88623 | HIGH | 7.5 | 0.2% | Sep 18, 2026 | NUUO Network Video Recorder 2.0.0 is vulnerable to arbitrary file read. In up.php, the url parameter submitted by the us... |
| CVE-2026-88622 | HIGH | 8.8 | 1.1% | Sep 18, 2026 | NUUO Network Video Recorder 2.0.0 is vulnerable to Command Injection in handle_import_privilege.php. |
| CVE-2026-79294 | MEDIUM | 6.1 | 0.5% | Sep 18, 2026 | Cross Site Scripting vulnerability in Moonshot AI Kimi version as of 2026-07-18 allows a remote attacker to execute arbi... |
| CVE-2026-62282 | MEDIUM | 6.5 | 0.3% | Sep 18, 2026 | OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and Slack int... |
| CVE-2026-93492 | MEDIUM | 5.3 | 0.6% | Sep 18, 2026 | A flaw was found in Netty's HTTP/2 HpackEncoder. A remote attacker can exploit this by sending HTTP/2 SETTINGS frames wi... |
| CVE-2026-93491 | HIGH | 7.5 | 0.4% | Sep 18, 2026 | A flaw was found in Netty's HttpServerCodec. A remote, unauthenticated attacker can exploit this vulnerability by pipeli... |
| CVE-2026-93488 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | A flaw was found in Netty. SpdySessionHandler accepts an unlimited number of concurrent remote-initiated streams because... |
| CVE-2026-28199 | LOW | 3.3 | — | Sep 18, 2026 | An authenticated user with access to the NetBackup Flex OS management shell could read arbitrary files from the underly... |
| CVE-2026-28198 | HIGH | 8.8 | — | Sep 18, 2026 | An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could bypass the cryptograp... |
| CVE-2026-28197 | HIGH | 8.8 | — | Sep 18, 2026 | An authenticated, low-privileged user with access to the NetBackup Flex OS management shell could supply a specially cr... |
| CVE-2026-21806 | LOW | 3.1 | — | Sep 18, 2026 | HCL BigFix Service Management is affected by an Administrative Session Concurrency vulnerability. The application allows... |
| CVE-2026-93578 | MEDIUM | 5.9 | — | Sep 18, 2026 | A flaw was found in Netty's Online Certificate Status Protocol (OCSP) Client. The client fails to verify the 'id-kp-OCSP... |
| CVE-2026-93575 | HIGH | 7.5 | 0.7% | Sep 18, 2026 | A flaw was found in Netty's MqttDecoder. An unauthenticated remote attacker can exploit this vulnerability by sending a ... |
| CVE-2026-93572 | HIGH | 7.5 | 0.6% | Sep 18, 2026 | A flaw was found in Netty's `RedisArrayAggregator` component. A remote attacker can exploit this vulnerability by sendin... |
| CVE-2026-93563 | HIGH | 7.5 | 0.6% | Sep 18, 2026 | A flaw was found in Netty's `SmtpResponseDecoder` component. A remote attacker, acting as a malicious or man-in-the-midd... |
| CVE-2026-93561 | MEDIUM | 6.5 | 0.3% | Sep 18, 2026 | A flaw was found in io.netty/netty-codec-memcache. The Memcache binary protocol codec incorrectly reads `keyLength` and ... |
| CVE-2026-81627 | HIGH | 8.2 | 0.2% | Sep 18, 2026 | A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c does not validate that the writable RAM alias rem... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now