2026 CVE Vulnerabilities
64,763 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15915 | MEDIUM | 6.2 | 0.2% | Sep 22, 2026 | IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of... |
| CVE-2026-96260 | MEDIUM | 6.5 | 0.4% | Sep 22, 2026 | Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request ... |
| CVE-2026-96259 | MEDIUM | 5.5 | 0.3% | Sep 22, 2026 | Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to apply the internal... |
| CVE-2026-95815 | MEDIUM | 6.3 | 0.2% | Sep 22, 2026 | OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as pub... |
| CVE-2026-95813 | MEDIUM | 6.1 | 0.3% | Sep 22, 2026 | e621ng versions before 26.09.16 pass untrusted request parameters directly to Rails url_for in PaginatorComponent and co... |
| CVE-2026-95812 | MEDIUM | 6.1 | 0.4% | Sep 22, 2026 | ClipBucket v5 before 5.5.3-#182 contains a reflected cross-site scripting vulnerability in the sort_link() helper functi... |
| CVE-2026-88020 | MEDIUM | 6.1 | 0.3% | Sep 22, 2026 | Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability ... |
| CVE-2026-77425 | MEDIUM | 4.3 | 0.3% | Sep 22, 2026 | Unleash is an open-source feature management platform. Prior to 8.0.3, POST /api/admin/projects/:projectId/features/:fea... |
| CVE-2026-76910 | MEDIUM | 5.3 | 0.4% | Sep 22, 2026 | Unleash is an open-source feature management platform. Prior to 8.0.3, cloneFeatureToggle and POST /api/admin/projects/:... |
| CVE-2026-75101 | MEDIUM | 6 | 0.4% | Sep 22, 2026 | An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed any authenticated user of ... |
| CVE-2026-88341 | MEDIUM | 5.5 | 0.2% | Sep 22, 2026 | A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files. An attacker can ... |
| CVE-2026-88339 | MEDIUM | 5.5 | 0.2% | Sep 22, 2026 | A NULL pointer dereference vulnerability exists in the gf_sg_vrml_field_clone() function of GPAC 2d7da22e (26.08-DEV). T... |
| CVE-2026-83805 | MEDIUM | 6.4 | 0.2% | Sep 22, 2026 | Nautobot is a Network Source of Truth and Network Automation Platform. From 3.0.0 until 3.1.8, the generic ApprovalWorkf... |
| CVE-2026-83801 | MEDIUM | 5.4 | 0.3% | Sep 22, 2026 | Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.37 and 3.1.8, a user with extras.add... |
| CVE-2026-79767 | MEDIUM | 5.5 | 0.4% | Sep 22, 2026 | Gardener implements the automated management and operation of Kubernetes clusters as a service. Prior to 1.142.6, 1.143.... |
| CVE-2026-76717 | MEDIUM | 5.3 | 0.4% | Sep 22, 2026 | A vulnerability exists in the Analytics and Location Engine (ALE) API that may allow for the disclosure of sensitive inf... |
| CVE-2026-76716 | MEDIUM | 5.3 | 0.5% | Sep 22, 2026 | Multiple vulnerabilities exist in the Analytics and Location Engine (ALE) that may allow for unauthorized access or deni... |
| CVE-2026-65829 | MEDIUM | 5.3 | 0.4% | Sep 22, 2026 | MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 7.3.0 ... |
| CVE-2026-63628 | MEDIUM | 6.9 | 0.4% | Sep 22, 2026 | mppx is a TypeScript interface for machine payments protocol. Prior to 0.8.2, the fee-payer cosigning path in src/tempo/... |
| CVE-2026-63627 | MEDIUM | 6.9 | 0.5% | Sep 22, 2026 | mppx is a TypeScript interface for machine payments protocol. Prior to 0.8.2, FeePayerPolicy in src/tempo/internal/fee-p... |
| CVE-2026-91129 | MEDIUM | 5.4 | 0.2% | Sep 22, 2026 | Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.2.3, the IPP ... |
| CVE-2026-89277 | MEDIUM | 5.5 | 0.3% | Sep 22, 2026 | CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an applicati... |
| CVE-2026-84396 | MEDIUM | 5.5 | 0.1% | Sep 22, 2026 | InDesign Desktop is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-s... |
| CVE-2026-77399 | MEDIUM | 6.5 | 0.5% | Sep 22, 2026 | icalendar is an RFC 5545 compatible parser and generator of iCalendar files for Python. From 6.1.0 until 7.2.2, vInt.fro... |
| CVE-2026-77272 | MEDIUM | 5.4 | 0.3% | Sep 22, 2026 | MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, th... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now