2026 CVE Vulnerabilities
64,763 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-67615 | HIGH | 8.8 | 1.0% | Sep 22, 2026 | openEQUELLA before 2026.1.0 contains an authenticated remote code execution vulnerability that allows any authenticated ... |
| CVE-2026-94574 | HIGH | 7.8 | 0.2% | Sep 22, 2026 | A local cross-user code execution vulnerability exists in GNU wget (Windows builds from eternallybored.org) due to a har... |
| CVE-2026-89281 | HIGH | 8.4 | 0.2% | Sep 22, 2026 | The Apache Lounge Windows distribution of Apache HTTP Server build contains a hardcoded configuration path vulnerability... |
| CVE-2026-88419 | HIGH | 8.8 | 0.5% | Sep 22, 2026 | An unrestricted upload of files with a dangerous type in the thumbnail-upload endpoint (/index.php?m=member&f=article&v=... |
| CVE-2026-88418 | HIGH | 8.8 | 0.3% | Sep 22, 2026 | CMSimple 5.24 ships with CSRF protection disabled by default, which turns csrfProtection() into a no-op on every state-c... |
| CVE-2026-88345 | HIGH | 7.5 | 0.4% | Sep 22, 2026 | An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers sche... |
| CVE-2026-88344 | HIGH | 7.5 | 0.4% | Sep 22, 2026 | An out-of-bounds read vulnerability exists in the schema lexer of flatcc 4c3b999e. When an exact-length FlatBuffers sche... |
| CVE-2026-88340 | HIGH | 7.6 | 0.2% | Sep 22, 2026 | An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vu... |
| CVE-2026-77322 | HIGH | 7.5 | 0.6% | Sep 22, 2026 | SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.3, WSConnection.Read in sip/transport_ws.go... |
| CVE-2026-76715 | HIGH | 7.1 | 0.3% | Sep 22, 2026 | A vulnerability in an administrative component of Analytics and Location Engine (ALE) is vulnerable to a man-in-the-midd... |
| CVE-2026-76714 | HIGH | 7.2 | 0.8% | Sep 22, 2026 | Vulnerabilities in the Analytics and Location Engine web interface allows remote authenticated users to run arbitrary co... |
| CVE-2026-76713 | HIGH | 7.2 | 0.6% | Sep 22, 2026 | A vulnerability exists in the maintenance restore functionality of Analytics and Location Engine (ALE). Successful explo... |
| CVE-2026-76712 | HIGH | 7.3 | 0.4% | Sep 22, 2026 | A vulnerability exists in the Analytics and Location Engine (ALE) that may allow for unauthorized access, information di... |
| CVE-2026-76711 | HIGH | 7.5 | 0.5% | Sep 22, 2026 | A vulnerability exists in an Analytics and Location Engine (ALE) component where the impacted process improperly process... |
| CVE-2026-76710 | HIGH | 7.5 | 0.5% | Sep 22, 2026 | A vulnerability exists in the Analytics and Location Engine (ALE) management interface that may allow for the disclosure... |
| CVE-2026-63104 | HIGH | 8.1 | — | Sep 22, 2026 | Kaneo versions 2.3.12 before 2.12.2 contain a missing authorization vulnerability that allows authenticated workspace me... |
| CVE-2026-62985 | HIGH | 7.5 | 0.5% | Sep 22, 2026 | request-filtering-agent is an http(s).Agent implementation that blocks requests to Private/Reserved IP addresses. Prior ... |
| CVE-2026-61570 | HIGH | 7.5 | 0.3% | Sep 22, 2026 | MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 5.5.5 ... |
| CVE-2026-59991 | HIGH | 7.5 | 0.6% | Sep 22, 2026 | psd-tools is a Python package for working with Adobe Photoshop PSD files. Prior to 1.17.4, PSDImage.composite() and PSDI... |
| CVE-2026-58268 | HIGH | 7.5 | 0.6% | Sep 22, 2026 | SIPGO is a library for writing SIP services in the GO language. Prior to 1.4.1, ParserStream.parseSingle in sip/parser_s... |
| CVE-2026-28325 | HIGH | 8.8 | 1.5% | Sep 22, 2026 | SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability ... |
| CVE-2026-95862 | HIGH | 7.5 | — | Sep 22, 2026 | A malicious actor with access to the network could exploit an Out-of-bounds Write vulnerability found in certain UniFi g... |
| CVE-2026-95861 | HIGH | 7.5 | — | Sep 22, 2026 | A malicious actor with access to the network could exploit an Uncontrolled Recursion vulnerability found in certain UniF... |
| CVE-2026-95831 | HIGH | 7.8 | 0.1% | Sep 22, 2026 | Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfu... |
| CVE-2026-94462 | HIGH | 7.1 | 0.4% | Sep 22, 2026 | Spree is an open source e-commerce solution built with Ruby on Rails. From 5.4.0 until 5.4.4 and 5.5.4, PATCH /api/v3/st... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now