2026 CVE Vulnerabilities
68,698 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-58197 | HIGH | 8.8 | 0.4% | Sep 18, 2026 | ToolHive is a utility designed to simplify the deployment and management of Model Context Protocol servers. Prior to Too... |
| CVE-2026-55556 | HIGH | 8.2 | 1.1% | Sep 18, 2026 | Rsyslog is a rocket-fast system for log processing. From 8.2110.0 until 8.2604.0, the optional imhttp module's parse_aut... |
| CVE-2026-46655 | HIGH | 7.8 | 0.2% | Sep 18, 2026 | virtio-win provides Windows paravirtualized drivers for QEMU and KVM. From mm210 until mm320, the Viosock driver permits... |
| CVE-2026-44639 | LOW | 3.7 | — | Sep 18, 2026 | NanoMQ is an MQTT broker. Prior to 0.24.14, NanoMQ's MQTT v5 property decoder in nng/src/supplemental/mqtt/mqtt_codec.c ... |
| CVE-2026-93737 | MEDIUM | 6.5 | 0.3% | Sep 18, 2026 | Azkaban through 4.0.0 omits project permission checks in the ScheduleServlet fetchSchedule action, allowing authenticate... |
| CVE-2026-93736 | MEDIUM | 4.3 | 0.3% | Sep 18, 2026 | Mealie before 3.21.0 fails to validate user ownership in the ratings and favorites endpoints, allowing authenticated att... |
| CVE-2026-93690 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | uri-js through 4.4.1 contains a denial of service vulnerability in the removeDotSegments function that loops infinitely ... |
| CVE-2026-93689 | MEDIUM | 5.5 | 0.1% | Sep 18, 2026 | WinFsp through 2.2.26215 contains a null pointer dereference vulnerability in the kernel driver's Fast I/O device contro... |
| CVE-2026-93688 | HIGH | 7.5 | 0.4% | Sep 18, 2026 | SGLang through 0.5.19 in prefill/decode disaggregation mode with Mooncake KV transfer backend fails to validate bootstra... |
| CVE-2026-93687 | HIGH | 7.5 | 0.4% | Sep 18, 2026 | braces through 3.0.3 contains a stack overflow vulnerability in the recursive AST walkers that lack depth guards. Attack... |
| CVE-2026-93532 | MEDIUM | 6.3 | 0.5% | Sep 18, 2026 | A security vulnerability has been detected in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf7... |
| CVE-2026-93531 | MEDIUM | 4.3 | — | Sep 18, 2026 | A weakness has been identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. This vu... |
| CVE-2026-88259 | HIGH | 7.5 | 0.3% | Sep 18, 2026 | CareCam CM2507 IP cameras do not require authentication for access to its network video streaming service. An unauthenti... |
| CVE-2026-86689 | MEDIUM | 5.9 | — | Sep 18, 2026 | Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active ... |
| CVE-2026-86520 | HIGH | 7.5 | — | Sep 18, 2026 | Bransys ELD is shipped with hardcoded MQTT credentials, which will grant read access to real-time data for every active ... |
| CVE-2026-84451 | MEDIUM | 6.5 | 0.5% | Sep 18, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, the no-icef full-item branch of un... |
| CVE-2026-84450 | MEDIUM | 4.3 | 0.4% | Sep 18, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.3, a crafted image item containing a ... |
| CVE-2026-84449 | LOW | 3.7 | 0.3% | Sep 18, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.19.6, Op_RGB24_32_to_YCbCr::convert_colorspace() ... |
| CVE-2026-84448 | MEDIUM | 4 | 0.2% | Sep 18, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, the public heif_region_item_add_region_inli... |
| CVE-2026-84447 | HIGH | 7.5 | — | Sep 18, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. In 1.23.1 and earlier, crafted grid, iovl, and iden referenc... |
| CVE-2026-84446 | HIGH | 7.5 | 0.5% | Sep 18, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, crafted HEIF sequence timing and edit-list ... |
| CVE-2026-84444 | HIGH | 7.4 | 0.4% | Sep 18, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1.23.2, when WITH_UNCOMPRESSED_CODEC is enabled, he... |
| CVE-2026-84400 | LOW | 3.1 | 0.1% | Sep 18, 2026 | CareCam CM2507 IP cameras contain an insufficiently protected network maintenance mechanism that can activate a remote d... |
| CVE-2026-84398 | HIGH | 7.5 | 0.2% | Sep 18, 2026 | CM2507 IP cameras accept an empty password for a privileged account exposed through its ONVIF management service. An att... |
| CVE-2026-84384 | HIGH | 7.5 | — | Sep 18, 2026 | libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.2, crafted HEIF or AVIF mime metadata... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now